CVE-2025-48046: Mici Network Co. Ltd Netfax Server

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.

Affected products

Published 2025-05-29. Last modified 2026-06-17.