CVE-2023-31460
Description
A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allow an authenticated attacker with internal network access to conduct a command injection attack due to insufficient restriction on URL parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
MiVoice Connect Mobility Router is vulnerable to command injection via URL parameters, allowing an authenticated internal attacker to execute arbitrary commands.
Vulnerability
A command injection vulnerability exists in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier [2]. The flaw is triggered by insufficient restriction on URL parameters, enabling an authenticated attacker with internal network access to inject arbitrary system commands within the context of the router component [1].
Exploitation
An attacker must have valid authentication credentials and internal network access to the vulnerable system [2]. The attack is carried out by crafting a malicious HTTP request with specially manipulated URL parameters that bypass input validation, causing the server to execute attacker-supplied commands on the underlying operating system [1].
Impact
Successful exploitation allows the attacker to execute arbitrary commands with the privileges of the affected service, leading to full compromise of the Mobility Router's operating system, including potential data disclosure, modification, and denial of service [2].
Mitigation
Mitel has released updated software versions to address this vulnerability; customers should update to the latest version as indicated in the product Security Bulletin [2]. No workarounds are documented in the available references [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Mitel/MiVoice Connectdescription
- Range: <=9.6.2208.101
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.