High severity8.8NVD Advisory· Published Jun 9, 2024· Updated Jun 17, 2026
CVE-2024-37570
CVE-2024-37570
Description
On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command. This leads to $() command execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:mitel:6869i_sip_firmware:4.5.0.41:*:*:*:*:*:*:*
- Mitel/6869idescription
Patches
Vulnerability mechanics
References
2- github.com/kwburns/CVE/tree/main/Mitel/5.0.0.1018nvdExploitThird Party Advisory
- github.com/kwburns/CVE/blob/main/Mitel/5.0.0.1018/code/exploit-firmware.pynvdProduct
News mentions
0No linked articles in our index yet.