Critical MICI NetFax Server Vulnerabilities Enable Remote Code Execution

A critical vulnerabilities in MICI Network Co., Ltd’s NetFax server versions prior to 3.0.1.0 that enable attackers to achieve remote code execution with root privileges.

The vulnerabilities, designated as CVE-2025-48045, CVE-2025-48046, and CVE-2025-48047, create an attack chain that begins with exposed default credentials and culminates in complete system compromise.

Despite responsible disclosure efforts spanning several months, the Taiwan-based vendor has declined to address these security issues, instead advising customers to avoid external network exposure.

The vulnerability sequence begins with CVE-2025-48045, a moderate-severity flaw that exposes default administrative credentials in cleartext through HTTP requests to the /client.php endpoint.

This credential disclosure occurs automatically during initial access and appears to support functionality for the ‘OneIn’ client application.

The exposed credentials provide attackers with the authentication necessary to exploit subsequent vulnerabilities in the chain.

Building upon this initial access, CVE-2025-48046 reveals stored SMTP passwords in cleartext through configuration file requests to /config.php.

SMTP passwords configured
SMTP passwords configured

While the user interface properly redacts sensitive information, the underlying configuration requests expose passwords without protection.

The most severe vulnerability, CVE-2025-48047, involves command injection through insufficient input sanitization of the backtick () character in configuration parameters[1]. Attackers can leverage a system testing function at /test.phpthat executes commands like 'ping' using data from the compromised configuration file, ultimately enabling remote code execution through tools likemkfifoandnc` binaries present on the system.

MICI NetFax Server Vulnerabilities

Following industry-standard responsible disclosure practices, Rapid7 researcher Anna Quinn discovered these vulnerabilities in January 2025 and initiated contact with MICI through multiple channels.

After unsuccessful direct outreach attempts, Rapid7 enlisted Taiwan’s Computer Emergency Response Team (TWCERT) as an intermediary to facilitate vendor communication.

Despite extensive coordination efforts extending through May 2025, MICI ultimately communicated through TWCERT that they “will not address the vulnerability in this product” and advised users against external network exposure.

The vendor further indicated they would responding to security inquiries regarding the NetFax product.

Mitigations

Rapid7’s internet scanning identified 34 NetFax systems exposed to public networks, with potentially higher numbers deployed on internal networks.

The research team also discovered related ‘CoFax Server’ systems using similar architecture, primarily located in Iran, though these systems did not exhibit the same vulnerabilities.

Given the vendor’s refusal to provide security updates, Rapid7 recommends organizations immediately change default credentials, restrict network access to essential internal segments only, and carefully evaluate the security risks of maintaining these devices in production environments.

The security firm has developed Metasploit modules for both unauthenticated and authenticated exploitation scenarios, which will be released in upcoming updates.

Organizations using Rapid7’s InsightVM and Nexpose solutions can assess their exposure through unauthenticated vulnerability checks available in the May 28, 2025 content release.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Mayura
Mayura
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Trending News

Related Stories