Home

Description

An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.

PUBLISHED Reserved 2025-05-15 | Published 2025-05-29 | Updated 2025-05-29 | Assigner rapid7




CRITICAL: 9.4CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

Default status
unknown

Any version before 3.0.1.0
affected

Credits

Anna Quinn, Security Consultant at Rapid7 finder

References

www.rapid7.com/...-server-product-vulnerabilities-not-fixed/

cve.org (CVE-2025-48047)

nvd.nist.gov (CVE-2025-48047)

Download JSON