CVE-2025-48045: Mici Network Co. Ltd Netfax Server
High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.
An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials.
Affected products
- Mici Network Co. Ltd Netfax Server: before 3.0.1.0 (fixed in 3.0.1.0)
Published 2025-05-29. Last modified 2026-06-17.