logo

Mitel warns of critical MiVoice MX-ONE authentication bypass flaw

ID: 559c3655-064e-5fd3-a6df-e1be026d67b3

STIX ID: report--559c3655-064e-5fd3-a6df-e1be026d67b3

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-07-24

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Mitel has published security updates addressing a critical authentication-bypass vulnerability in MiVoice MX-ONE Provisioning Manager (affecting versions 7.3 through 7.8 SP1) that could allow unauthenticated attackers to obtain administrator access, and disclosed a high-severity SQL injection in MiCollab (CVE-2025-52914); mitigations include applying vendor patches and restricting access to the services, and the advisory notes past MiCollab flaws that were exploited in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.