Mitel 6800, 6900, and 6900w Series SIP Phones Unauthenticated File Upload Vulnerability

Vulnerability

An unauthenticated file upload vulnerability has been identified in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, all running versions through 6.4 SP4. This vulnerability allows an unauthenticated attacker to upload arbitrary WAV files due to missing authentication mechanisms. Exploitation of this vulnerability could lead to storage exhaustion on the affected phones, without disrupting their availability or normal operation.

Impact

Successful exploitation allows for unauthorized file uploads, which could fill the phone's storage capacity, potentially leading to issues with storage management or file handling.

Remediation

Users are advised to upgrade to Mitel 6800 Series, 6900 Series, or 6900w Series SIP Phones version R6.4.0.SP5 (4.0.5013) or later. For the Mitel 6970 Conference Unit, upgrade to version R6.4.0.SP5 (4.0.5013) or version V1 R0.2.0 or later, depending on the product's usage context. Consult the Mitel Knowledge Base article SO8496 for detailed update instructions.

Added: Jul 23, 2025, 7:18 PM
Updated: Jul 23, 2025, 8:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
7.0
remediation
7.9
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.