Mitel Networks has issued security updates to address a critical authentication bypass vulnerability in its MiVoice MX-ONE platform, which could allow attackers to gain unauthorized admin access. Additionally, a high-severity SQL injection flaw in MiCollab underscores ongoing security concerns across Mitel’s enterprise communication products. #MiVoiceMXONE #MitelSecurity #MiCollabVulnerability
Keypoints
- Mitel released security patches for a critical authentication bypass in MiVoice MX-ONE.
- The vulnerability affects versions 7.3 to 7.8 SP1 and can be exploited via low-complexity, unauthenticated attacks.
- Customers are advised to restrict access to the Provisioning Manager and deploy within trusted networks.
- A high-severity SQL injection vulnerability (CVE-2025-52914) was also disclosed in the MiCollab platform.
- Mitel products service over 60,000 customers worldwide, spanning various critical sectors.