CVE-2025-48026: Path Traversal
A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow an attacker to read files from the underlying OS and obtain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48026?
CVE-2025-48026 is categorized as a high severity vulnerability due to its potential for a path traversal attack.
How do I fix CVE-2025-48026?
To fix CVE-2025-48026, it is recommended to update Mitel OpenScape Xpressions to a patched version beyond V7R1 FR5 HF43 P913.
What types of attacks can be executed using CVE-2025-48026?
CVE-2025-48026 allows unauthenticated attackers to execute path traversal attacks, potentially leading to the exposure of sensitive files.
Which versions of Mitel OpenScape Xpressions are affected by CVE-2025-48026?
CVE-2025-48026 affects Mitel OpenScape Xpressions up to and including version V7R1 FR5 HF43 P913.
Is authentication required to exploit CVE-2025-48026?
No, CVE-2025-48026 can be exploited by unauthenticated attackers due to insufficient input validation.