CVE-2025-15070
Description
Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse.
This issue affects Web Fax: from 3.0 before 3.0.1
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2025-15070 is a medium-severity vulnerability in Gmission Web Fax that exposes sensitive information and enables authentication abuse due to missing authorization checks.
Vulnerability
Overview
CVE-2025-15070 is an authorization bypass vulnerability in Gmission Web Fax, affecting versions from 3.0 before 3.0.1. The software is a network-based fax solution for sending and receiving fax documents, managing fax info, and handling shared and personal fax inboxes [1]. The root cause is missing authorization checks, which allows an unauthenticated or unauthorized actor to access sensitive information [1].
Exploitation and
Attack Surface
This vulnerability can be exploited over the network without requiring authentication, as the description indicates 'Authentication Abuse' and 'Missing Authorization' [1]. An attacker who can reach the application can abuse the lack of proper access controls to access data that should be protected [1]. The attack vector is likely simple, as no special privileges are needed to initiate the exploit [1].
Impact
An attacker exploiting this flaw can gain unauthorized access to sensitive information, such as fax documents, fax management data, and personal or shared fax inbox contents [1]. This can lead to leakage of confidential communications and compromise of user privacy. The CVSS v3 score of 5.5 (Medium) reflects the potential for significant information disclosure [1].
Mitigation
The vulnerability is fixed in Web Fax version 3.0.1 and later [1]. Users should upgrade to the patched version immediately. There are no known workarounds; applying the update is the only reliable way to remediate the issue [1]. This CVE is not listed in the CISA Known Exploited Vulnerabilities catalog as of the publication date [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Gmission/Web Faxv5Range: 3.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.gmission.co.kr/fax1nvdProduct
News mentions
0No linked articles in our index yet.