CVE-2024-28066

HIGH
Published Apr 8, 2024 Modified Jun 18, 2025 CWE-259 CWE-1391

Description

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

Is your site exposed to CVE-2024-28066?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

8.8
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-259 CWE-259
CWE-1391 CWE-1391

Affected Products

Vendor Product
mitel 6940w_firmware
mitel 6940w
mitel 6930w_firmware
mitel 6930w
mitel 6920w_firmware
mitel 6920w
mitel 6970_firmware
mitel 6970
mitel 6915_firmware
mitel 6915
mitel 6910_firmware
mitel 6910
mitel 6905_firmware
mitel 6905
mitel openscape_cp710_firmware
mitel openscape_cp710
mitel openscape_cp410_firmware
mitel openscape_cp410
mitel openscape_cp210_firmware
mitel openscape_cp210
mitel openscape_cp110_firmware
mitel openscape_cp110
mitel openscape_cpx10_firmware
mitel openscape_cpx10
mitel openscape_dect_firmware
mitel openscape_dect
mitel 700d_dect_firmware
mitel 700d_dect

References

Frequently Asked Questions

What is CVE-2024-28066? +
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password). It has a CVSS v3.1 base score of 8.8 (HIGH).
How severe is CVE-2024-28066? +
CVE-2024-28066 has a CVSS v3.1 score of 8.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-28066? +
CVE-2024-28066 affects products from mitel, specifically: 6905, 6905_firmware, 6910, 6910_firmware, 6915, 6915_firmware, 6920w, 6920w_firmware, 6930w, 6930w_firmware, 6940w, 6940w_firmware, 6970, 6970_firmware, 700d_dect, 700d_dect_firmware, openscape_cp110, openscape_cp110_firmware, openscape_cp210, openscape_cp210_firmware, openscape_cp410, openscape_cp410_firmware, openscape_cp710, openscape_cp710_firmware, openscape_cpx10, openscape_cpx10_firmware, openscape_dect, openscape_dect_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-28066? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-28066 — free, no signup required.