CVE-2025-48046: Mici Network Co. Ltd Netfax Server
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.
Affected products
- Mici Network Co. Ltd Netfax Server: before 3.0.1.0 (fixed in 3.0.1.0)
Published 2025-05-29. Last modified 2026-06-17.