CVE-2025-47187

7.5

Mitel · 6800 Series, 6900 Series, 6900w Series SIP Phones, and 6970 Conference Unit

A file upload vulnerability in Mitel SIP phones allows unauthenticated attackers to exhaust device storage by uploading arbitrary WAV files.

Executive summary

Unauthenticated attackers can potentially cause a denial of service on Mitel SIP phones by exploiting a missing authentication check to perform arbitrary file uploads.

Vulnerability

The vulnerability exists due to a lack of authentication mechanisms on the affected devices, which permits an unauthenticated remote attacker to upload arbitrary WAV files to the phone system.

Business impact

While the CVSS score of 7.5 indicates a high severity, the impact is primarily limited to storage exhaustion, which could degrade the availability or operational capacity of the telephony units. Successful exploitation may lead to localized denial of service conditions, potentially disrupting business communications and requiring administrative intervention to clear the affected storage.

Remediation

Immediate Action: Review the official Mitel security advisory (MISA-2025-0004) and apply the latest firmware updates as soon as they are made available by the vendor.

Proactive Monitoring: Monitor network traffic for unusual file upload requests targeting SIP phone interfaces and inspect device storage logs for unexpected file accumulation.

Compensating Controls: Restrict access to the management interfaces of SIP phones to authorized administrative subnets and implement network segmentation to prevent unauthorized remote access.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for service disruption, administrators should prioritize the identification of all affected Mitel hardware within their network environment. Once the vendor releases the necessary firmware patches, they should be deployed immediately to restore proper authentication controls and secure the affected units against unauthorized file uploads.

Sources