VYPR
Unrated severityNVD Advisory· Published May 24, 2023· Updated Jan 31, 2025

CVE-2023-31460

CVE-2023-31460

Description

A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allow an authenticated attacker with internal network access to conduct a command injection attack due to insufficient restriction on URL parameters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

MiVoice Connect Mobility Router is vulnerable to command injection via URL parameters, allowing an authenticated internal attacker to execute arbitrary commands.

Vulnerability

A command injection vulnerability exists in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier [2]. The flaw is triggered by insufficient restriction on URL parameters, enabling an authenticated attacker with internal network access to inject arbitrary system commands within the context of the router component [1].

Exploitation

An attacker must have valid authentication credentials and internal network access to the vulnerable system [2]. The attack is carried out by crafting a malicious HTTP request with specially manipulated URL parameters that bypass input validation, causing the server to execute attacker-supplied commands on the underlying operating system [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands with the privileges of the affected service, leading to full compromise of the Mobility Router's operating system, including potential data disclosure, modification, and denial of service [2].

Mitigation

Mitel has released updated software versions to address this vulnerability; customers should update to the latest version as indicated in the product Security Bulletin [2]. No workarounds are documented in the available references [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.