VYPR

NetFax Server

by MICi

CVEs (3)

  • CVE-2025-48047CriMay 29, 2025
    risk 0.62cvss —epss 0.16

    An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.

  • CVE-2025-48045HigMay 29, 2025
    risk 0.57cvss —epss 0.01

    An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials.

  • CVE-2025-48046MedMay 29, 2025
    risk 0.34cvss —epss 0.01

    An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.