Description
A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown code of the component biz.faxapp.app. Such manipulation leads to path traversal. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Product status
Timeline
| 2025-12-14: | Advisory disclosed |
| 2025-12-14: | VulDB entry created |
| 2025-12-14: | VulDB entry last update |
Credits
Lu1u (VulDB User)
References
vuldb.com/?id.336417 (VDB-336417 | Municorn FAX App biz.faxapp.app path traversal)
vuldb.com/?ctiid.336417 (VDB-336417 | CTI Indicators (IOB, IOC, TTP))
vuldb.com/?submit.706215 (Submit #706215 | MUNICORN LIMITED(https://comfax.com/) FAX App: Send Faxes from Phone APP (biz.faxapp.app) Version:V3.27.0 Path Traversal)
github.com/Secsys-FDU/AF_CVEs/issues/3
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.