This is a vulnerability writeup describing an unauthenticated command execution flaw in Mitel's AWC (Audio and Web Conferencing) web interface. The PoC demonstrates command injection via URL parameters to execute arbitrary Unix commands.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:Mitel Audio and Web Conferencing (AWC)
No auth needed
Prerequisites:Network access to the target system · Mitel AWC web interface exposed