
MICI NetFax Server Product Vulnerabilities (NOT FIXED)
Last updated at Fri, 30 May 2025 18:47:35 GMT In the course of a penetration testing engagement, Rapid7 discovered three vulnerabilities in MICI Network Co., Ltd’s NetFax server versions < 3.0.1.0. These issues allowed for an authenticated attack chain resulting in Remote Code Execution (RCE) against the device as the root user. While authentication is…