Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Luma launches AI-powered production studio with faith-focused Wonder Project

    April 17, 2026

    Factory hits $1.5B valuation to build AI coding for enterprises

    April 16, 2026

    Slash, a Ramp competitor founded by teenagers, raises $100M at $1.4B valuation

    April 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Luma launches AI-powered production studio with faith-focused Wonder Project
    • Factory hits $1.5B valuation to build AI coding for enterprises
    • Slash, a Ramp competitor founded by teenagers, raises $100M at $1.4B valuation
    • Upscale AI in talks to raise at $2B valuation, says report
    • From the Startup Battlefield stage to the International Space Station: geCKo Materials built a sticky product
    • This energy startup’s bet on 100-year-old grid tech is paying off
    • You’ve heard of hybrid cars. Now meet a hybrid cement plant.
    • AI learning app Gizmo levels up with 13M users and a $22M investment
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Guides»Mitel warns critical security flaw could let hackers completely bypass logins
    Guides

    Mitel warns critical security flaw could let hackers completely bypass logins

    TechurzBy TechurzJuly 25, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A hacker wearing a hoodie sitting at a computer, his face hidden.
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • A bug in MiVoice MX-ONE granted admin access
    • A vulnerability in MiCollab allows arbitrary command execution
    • Patches were released for both, so users should update now

    Mitel Networks has patched two important vulnerabilities in its products that could be abused to gain admin access and deploy malicious code on compromised endpoints.

    In a security advisory, Mitel said it discovered a critical-severity authentication bypass flaw in MiVoice MX-ONE, its enterprise-grade Unified Communications & Collaboration (UCC) platform. MX-ONE is designed to scale from hundreds to over 100,000 users in a single distributed or centralized SIP-based system, and supports both on‑premises and private/public cloud deployments.

    An improper access control weakness was discovered in the Provisioning Manager component, which could allow threat actors to gain admin access without victim interaction.


    You may like

    Patches released

    At press time, the bug has not yet been assigned a CVE, but it was given a 9.4/10 (critical) severity score.

    It affects versions 7.3 (7.3.0.0.50) to 7.8 SP1 (7.8.1.0.14), and was addressed in versions 7.8 (MXO-15711_78SP0) and 7.8 SP1 (MXO-15711_78SP1).

    “Do not expose the MX-ONE services directly to the public internet. Ensure that the MX-ONE system is deployed within a trusted network. The risk may be mitigated by restricting access to the Provisioning Manager service,” Mitel said in the advisory.

    The second flaw it fixed is a high-severity SQL injection vulnerability found in MiCollab, the company’s collaboration platform. It is tracked as CVE-2025-52914, and allows threat actors to execute arbitrary SQL database commands.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    The good news is that there is still no evidence that these two flaws have been abused in the wild, so it’s safe to assume no threat actors found it yet.

    However, many cybercriminals simply wait for the news of a vulnerability to break, betting that many organizations fail to patch their systems on time.

    While this somewhat reduces the number of potential victims, it makes compromising the remaining ones a lot easier, and that number is often still high enough to give the threat actors incentive.

    Via BleepingComputer

    You might also like

    bypass Completely Critical flaw Hackers logins Mitel Security warns
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleShould Silicon Valley celebrate Trump’s AI plans?
    Next Article Today’s NYT Wordle Hints, Answer and Help for July 25 #1497
    Techurz
    • Website

    Related Posts

    Opinion

    Conntour raises $7M from General Catalyst, YC to build an AI search engine for security video systems

    March 26, 2026
    Opinion

    Delve did the security compliance on LiteLLM, an AI project hit by malware

    March 26, 2026
    Opinion

    Databricks bought two startups to underpin its new AI security product

    March 24, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Luma launches AI-powered production studio with faith-focused Wonder Project

    April 17, 2026

    Factory hits $1.5B valuation to build AI coding for enterprises

    April 16, 2026

    Slash, a Ramp competitor founded by teenagers, raises $100M at $1.4B valuation

    April 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.