Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-26143

97
FAUCET Score

CVE-2022-26143 is a critical vulnerability affecting the TP-240 component in Mitel MiCollab and MiVoice Business Express, allowing remote attackers to obtain sensitive information and cause denial of service. With a CVSS score of 9.8 (CRITICAL), it requires no authentication or user interaction, enabling high impact to confidentiality, integrity, and availability. This vulnerability has been actively exploited in the wild, notably in the TP240PhoneHome DDoS attack, and has garnered significant community and media attention, with Nuclei templates available for detection.

Impacted Technologies

VendorProductVersion(s)CPE
< 9.4CPE matchmatch criteria
cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:*
9.4CPE matchmatch criteria
cpe:2.3:a:mitel:micollab:9.4:-:*:*:*:-:*:*
9.4CPE matchmatch criteria
cpe:2.3:a:mitel:micollab:9.4:sp1:*:*:*:-:*:*
<= 8.1CPE matchmatch criteria
cpe:2.3:a:mitel:mivoice_business_express:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
87.56%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Mar 25, 2022
Nuclei: CVE-2022-26143 · Oct 27, 2025
This CVE's current EPSS score of 0.8757 is in the 99th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
arstechnica.com / information-technology/2022/03/ddosers-use-new-method-capable-of-amplifying-traffic-by-a-factor-of-4-billion
ExploitPress/Media CoverageThird Party Advisory
blog.cloudflare.com / cve-2022-26143
MitigationThird Party Advisory
news.ycombinator.com / item
Issue TrackingThird Party Advisory
team-cymru.com / blog/2022/03/08/record-breaking-ddos-potential-discovered-cve-2022-26143
Broken LinkMitigationThird Party Advisory
akamai.com / blog/security/phone-home-ddos-attack-vector
MitigationThird Party Advisory
mitel.com / en-ca/support/security-advisories/mitel-product-security-advisory-22-0001
Vendor Advisory
shadowserver.org / news/cve-2022-26143-tp240phonehome-reflection-amplification-ddos-attack-vector
MitigationThird Party Advisory