CVE-2025-48047: Mici Network Co. Ltd Netfax Server
Critical severity, CVSS 9.4. EPSS: 15.7% chance of exploitation in the next 30 days.
An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.
Affected products
- Mici Network Co. Ltd Netfax Server: before 3.0.1.0 (fixed in 3.0.1.0)
Published 2025-05-29. Last modified 2026-06-17.