CVE-2024-41710

mitel 6940_sip_firmware, mitel 6905_sip_firmware, mitel 6910_sip_firmware

Published 12 Aug 2024 · updated 17 Jun 2026 · Analyzed

7.2 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 12 Feb 2025, with a remediation deadline of 5 Mar 2025 for US federal agencies.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

References