Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Fuse raises $25M to disrupt aging loan origination systems used by US credit unions

    March 16, 2026

    Apple acquires video editing software company MotionVFX

    March 16, 2026

    Another deep tech chip startup becomes a unicorn: Frore hits $1.64B

    March 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Fuse raises $25M to disrupt aging loan origination systems used by US credit unions
    • Apple acquires video editing software company MotionVFX
    • Another deep tech chip startup becomes a unicorn: Frore hits $1.64B
    • Walmart-backed PhonePe shelves IPO as global tensions rattle markets
    • Google, Accel India accelerator choses 5 startups and none are ‘AI wrappers’
    • Unacademy to be acquired by upGrad in share-swap deal as India’s edtech sector consolidates
    • Wiz investor unpacks Google’s $32B acquisition
    • US Army announces contract with Anduril worth up to $20B
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Guides»Mitel warns critical security flaw could let hackers completely bypass logins
    Guides

    Mitel warns critical security flaw could let hackers completely bypass logins

    TechurzBy TechurzJuly 25, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A hacker wearing a hoodie sitting at a computer, his face hidden.
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • A bug in MiVoice MX-ONE granted admin access
    • A vulnerability in MiCollab allows arbitrary command execution
    • Patches were released for both, so users should update now

    Mitel Networks has patched two important vulnerabilities in its products that could be abused to gain admin access and deploy malicious code on compromised endpoints.

    In a security advisory, Mitel said it discovered a critical-severity authentication bypass flaw in MiVoice MX-ONE, its enterprise-grade Unified Communications & Collaboration (UCC) platform. MX-ONE is designed to scale from hundreds to over 100,000 users in a single distributed or centralized SIP-based system, and supports both on‑premises and private/public cloud deployments.

    An improper access control weakness was discovered in the Provisioning Manager component, which could allow threat actors to gain admin access without victim interaction.


    You may like

    Patches released

    At press time, the bug has not yet been assigned a CVE, but it was given a 9.4/10 (critical) severity score.

    It affects versions 7.3 (7.3.0.0.50) to 7.8 SP1 (7.8.1.0.14), and was addressed in versions 7.8 (MXO-15711_78SP0) and 7.8 SP1 (MXO-15711_78SP1).

    “Do not expose the MX-ONE services directly to the public internet. Ensure that the MX-ONE system is deployed within a trusted network. The risk may be mitigated by restricting access to the Provisioning Manager service,” Mitel said in the advisory.

    The second flaw it fixed is a high-severity SQL injection vulnerability found in MiCollab, the company’s collaboration platform. It is tracked as CVE-2025-52914, and allows threat actors to execute arbitrary SQL database commands.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    The good news is that there is still no evidence that these two flaws have been abused in the wild, so it’s safe to assume no threat actors found it yet.

    However, many cybercriminals simply wait for the news of a vulnerability to break, betting that many organizations fail to patch their systems on time.

    While this somewhat reduces the number of potential victims, it makes compromising the remaining ones a lot easier, and that number is often still high enough to give the threat actors incentive.

    Via BleepingComputer

    You might also like

    bypass Completely Critical flaw Hackers logins Mitel Security warns
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleShould Silicon Valley celebrate Trump’s AI plans?
    Next Article Today’s NYT Wordle Hints, Answer and Help for July 25 #1497
    Techurz
    • Website

    Related Posts

    Opinion

    Mandiant’s founder just raised $190M for his autonomous AI agent security startup

    March 10, 2026
    Opinion

    Fig Security emerges from stealth with $38M to help security teams deal with change

    March 3, 2026
    Opinion

    Google VP warns that two types of AI startups may not survive

    February 21, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202515 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202515 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Fuse raises $25M to disrupt aging loan origination systems used by US credit unions

    March 16, 2026

    Apple acquires video editing software company MotionVFX

    March 16, 2026

    Another deep tech chip startup becomes a unicorn: Frore hits $1.64B

    March 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.