CVE-2025-47187
7.5Mitel · 6800 Series, 6900 Series, 6900w Series SIP Phones, and 6970 Conference Unit
A file upload vulnerability in Mitel SIP phones allows unauthenticated attackers to exhaust device storage by uploading arbitrary WAV files.
Executive summary
Unauthenticated attackers can potentially cause a denial of service on Mitel SIP phones by exploiting a missing authentication check to perform arbitrary file uploads.
Vulnerability
The vulnerability exists due to a lack of authentication mechanisms on the affected devices, which permits an unauthenticated remote attacker to upload arbitrary WAV files to the phone system.
Business impact
While the CVSS score of 7.5 indicates a high severity, the impact is primarily limited to storage exhaustion, which could degrade the availability or operational capacity of the telephony units. Successful exploitation may lead to localized denial of service conditions, potentially disrupting business communications and requiring administrative intervention to clear the affected storage.
Remediation
Immediate Action: Review the official Mitel security advisory (MISA-2025-0004) and apply the latest firmware updates as soon as they are made available by the vendor.
Proactive Monitoring: Monitor network traffic for unusual file upload requests targeting SIP phone interfaces and inspect device storage logs for unexpected file accumulation.
Compensating Controls: Restrict access to the management interfaces of SIP phones to authorized administrative subnets and implement network segmentation to prevent unauthorized remote access.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for service disruption, administrators should prioritize the identification of all affected Mitel hardware within their network environment. Once the vendor releases the necessary firmware patches, they should be deployed immediately to restore proper authentication controls and secure the affected units against unauthorized file uploads.