CVE-2025-48047: Mici Network Co. Ltd Netfax Server

Critical severity, CVSS 9.4. EPSS: 15.7% chance of exploitation in the next 30 days.

An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.

Affected products

Published 2025-05-29. Last modified 2026-06-17.