CVE-2025-48045: Mici Network Co. Ltd Netfax Server

High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.

An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials.

Affected products

Published 2025-05-29. Last modified 2026-06-17.