CVE-2025-52913: Path Traversal
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52913?
The severity of CVE-2025-52913 is considered high due to the potential for unauthorized access through a path traversal attack.
How do I fix CVE-2025-52913?
To fix CVE-2025-52913, update the Mitel MiCollab software to version 9.8 SP3 or later.
What type of attack does CVE-2025-52913 allow?
CVE-2025-52913 allows for a path traversal attack due to insufficient input validation.
Who is affected by CVE-2025-52913?
CVE-2025-52913 affects users of Mitel MiCollab versions up to and including 9.8 SP2 (9.8.2.12).
Can CVE-2025-52913 be exploited by authenticated users?
No, CVE-2025-52913 can be exploited by unauthenticated attackers, making it particularly dangerous.