← Vulnerability feed

Vulnerability record · CVE-2024-41710 · published 12 August 2024

CVE-2024-41710: Mitel SIP Phones argument injection in boot process

Mitel · 6970 Firmware

Mitel 6800, 6900 and 6900w Series SIP Phones (including the 6970 Conference Unit) through R6.4.0.HF1 fail to sanitize parameters during the boot process, allowing argument injection. An attacker who already holds administrative privileges can turn that weakness into arbitrary command execution on the phone. Because the affected devices are desk phones, compromise gives a foothold on the voice network rather than a single user endpoint.

7.2 CVSS 3.1 High CISA KEV since 12 Feb 2025 EPSS 42% · top 1.4% CWE-88 · Argument injection
7.2CVSS 3.1 base score
42%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
15Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 7.2, CISA KEV listing with a passed remediation deadline, a public exploit reference, and a 98.6th-percentile EPSS score make this a high-priority patch despite the admin-privilege requirement.

What it is

Mitel 6800, 6900 and 6900w Series SIP Phones (including the 6970 Conference Unit) through R6.4.0.HF1 fail to sanitize parameters during the boot process, allowing argument injection. An attacker who already holds administrative privileges can turn that weakness into arbitrary command execution on the phone. Because the affected devices are desk phones, compromise gives a foothold on the voice network rather than a single user endpoint.

Impact

An authenticated administrator can execute arbitrary commands in the context of the system, gaining full control of the phone's operating environment. That control can be used to alter device behavior, pivot into the voice VLAN, or tamper with communications.

Attack surface

The flaw is network-reachable (AV:N) with low attack complexity and no user interaction, but it requires high privileges (PR:H), meaning the attacker must already be an authenticated administrative user on the device. It is not a pre-auth or remote-unauthenticated path.

Exploitation

CVE-2024-41710 is listed in CISA KEV with a 2025-02-12 addition and a 2025-03-05 remediation due date, and a public third-party exploit reference exists. EPSS is 0.41646 (98.6th percentile), indicating high predicted exploitation activity; CISA records no known ransomware campaign use.

What to do

  • Upgrade affected 6800/6900/6900w Series SIP Phones and the 6970 Conference Unit to a firmware release above R6.4.0.HF1 per the Mitel advisory; if no fixed firmware is available, follow CISA guidance and discontinue use.
  • Restrict administrative access to phone web/management interfaces to a dedicated management VLAN and trusted hosts only.
  • Rotate and strengthen administrative credentials on all affected phones, since exploitation requires admin privilege.
  • Monitor Mitel security advisory 24-0019 and CISA KEV for updated fixed versions and required actions.
  • Segment voice devices from general user and server networks to limit lateral movement if a phone is compromised.

Detection

  • Review phone and management logs for unexpected configuration changes or boot parameter modifications on 6800/6900/6900w devices.
  • Alert on anomalous outbound connections or command execution artifacts originating from SIP phone IP addresses.
  • Audit administrative logins to phone management interfaces for unusual source addresses or times.
  • Inventory firmware versions across affected models and flag any device still at or below R6.4.0.HF1.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-41710 to the Known Exploited Vulnerabilities catalog on 12 February 2025 as "Mitel SIP Phones Argument Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 5 March 2025.

Affected products

15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-41710 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-37569Mitel 6869i sip firmware command injection vulnerabilityAn issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname …EPSS 3.2%8.8CVE-2024-37570Mitel 6869i sip firmware command injection vulnerabilityOn Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (se…EPSS 1.1%8.1CVE-2020-27639Mitel 6873i sip firmware vulnerabilityThe Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within…EPSS 0.52%6.8CVE-2022-29855Mitel 6873i sip firmware vulnerabilityMitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Seri…EPSS 0.74%9.2CVE-2026-86060MikroTik RouterOS SSH login argument injection privilege escalationRouterOS mishandles arguments in the SSH login path when a username begins with a prohibited character, allowing the trusted policy mask to be altere…KEVEPSS 1.8%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed8.8CVE-2022-36804Atlassian Bitbucket Server and Data Center API command injectionMultiple API endpoints in Atlassian Bitbucket Server and Data Center fail to properly neutralize command and argument input, allowing OS command inje…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2024-41710), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.