Digital Canyon 发现了一个漏洞,该漏洞允许攻击者使系统加载由攻击者控制的 .so 文件,而非预期的合法模块。该加载机制依赖于可预测的模块名称,且未充分验证文件的来源或完整性。因此,一个使用预期名称的恶意共享对象可被特权进程加载。随后,该模块代码将在该进程的上下文和权限下执行,从而导致任意代码执行,并使 Mitel Linux 虚拟机遭到完全接管。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mitel | Mitel MiVoice Office 400 | 11.0.96.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104805 | 8.5 HIGH | Mitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to Root Code Exec |
| CVE-2026-104706 | 8.4 HIGH | Mitel MiVoice Office 400 view system files path traversal |
| CVE-2026-104810 | 8.4 HIGH | Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability |
| CVE-2026-104811 | 8.4 HIGH | Mitel MiVoice Office 400 Music on Hold WAV File Upload Code Execution |
| CVE-2026-104806 | 5.5 MEDIUM | Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure |
| CVE-2026-104807 | 1.9 LOW | Mitel MiVoice Office 400 stored Cross-Site Scripting |
| CVE-2026-104808 | 1.9 LOW | Mitel MiVoice Office 400 stored Cross-Site Scripting |
No comments yet