PatchSiren cyber security CVE debrief
CVE-2025-1782 ifax CVE debrief
A critical authentication-bypassed remote code execution vulnerability exists in HylaFAX Enterprise Web Interface and AvantFAX. The language form element fails to sanitize input before PHP inclusion, enabling authenticated attackers to execute arbitrary code as the web server user. CVSS 9.9 reflects network attack vector, low complexity, and high impact across confidentiality, integrity, and availability with changed scope.
- Vendor
- ifax
- Product
- HylaFAX
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-14
- Original CVE updated
- 2026-05-26
- Advisory published
- 2025-04-14
- Advisory updated
- 2026-05-26
Who should care
Organizations operating HylaFAX Enterprise or AvantFAX web interfaces, particularly those with external user access or multi-tenant deployments. Security teams managing legacy fax infrastructure modernized with web frontends. Hosting providers offering fax-as-a-service platforms.
Technical summary
The vulnerability stems from insufficient sanitization of the language form element in PHP-based fax web interfaces. An authenticated attacker can manipulate this parameter to include arbitrary files through PHP's include/require mechanisms, achieving code execution with web server privileges. The attack requires valid credentials but no user interaction, with network-based exploitation path and scope change indicating potential container or virtualized environment impact.
Defensive priority
critical
Recommended defensive actions
- Apply vendor security patches from iFax when available
- Implement strict input validation on language selection parameters
- Deploy web application firewall rules to detect file inclusion patterns
- Review and restrict file system permissions for web server processes
- Enable comprehensive logging for authentication and file access events
- Conduct code audit for similar inclusion vulnerabilities in customizations
Evidence notes
NVD entry published 2025-04-14 with CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H vector. Vendor security advisory referenced via iFax. CWE-94 (Improper Control of Generation of Code) classified as primary weakness. No KEV listing as of source data.
Official resources
-
CVE-2025-1782 CVE record
CVE.org
-
CVE-2025-1782 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2025-04-14