VYPR

NetFax Server

by MICi

CVEs (3)

  • CVE-2025-48047CriMay 29, 2025
    risk 0.62cvss epss 0.14

    An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.

  • CVE-2025-48045HigMay 29, 2025
    risk 0.57cvss epss 0.01

    An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials.

  • CVE-2025-48046MedMay 29, 2025
    risk 0.34cvss epss 0.00

    An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.