Mitel warns of critical MiVoice MX-ONE authentication bypass flaw

Mitel warns of critical MiVoice MX-ONE authentication bypass flaw

Mitel Networks has issued security updates to address a critical authentication bypass vulnerability in its MiVoice MX-ONE platform, which could allow attackers to gain unauthorized admin access. Additionally, a high-severity SQL injection flaw in MiCollab underscores ongoing security concerns across Mitel’s enterprise communication products. #MiVoiceMXONE #MitelSecurity #MiCollabVulnerability

Keypoints

  • Mitel released security patches for a critical authentication bypass in MiVoice MX-ONE.
  • The vulnerability affects versions 7.3 to 7.8 SP1 and can be exploited via low-complexity, unauthenticated attacks.
  • Customers are advised to restrict access to the Provisioning Manager and deploy within trusted networks.
  • A high-severity SQL injection vulnerability (CVE-2025-52914) was also disclosed in the MiCollab platform.
  • Mitel products service over 60,000 customers worldwide, spanning various critical sectors.

Read More: https://www.bleepingcomputer.com/news/security/mitel-warns-of-critical-mivoice-mx-one-authentication-bypass-flaw/