Junglewise Threat Intelligence

CVE-2025-0645: Narkom Pyxis Signage unrestricted file upload

CVE-2025-0645 · Severity: high · CVSS 7.2 · Published 2025-11-20

Executive brief

Pyxis Signage, a digital signage management platform, contains a security flaw that allows high-privileged users to upload dangerous file types. This could allow an attacker to bypass intended access controls and gain unauthorized access to system functions. If exploited, this could lead to a full compromise of the signage system, affecting the integrity of displayed content and overall service availability.

Technical details

An unrestricted upload of file with dangerous type (CWE-434) exists in Narkom Pyxis Signage through version 31012025. The vulnerability allows an attacker with high privileges (PR:H) to upload malicious files, which subsequently enables the bypassing of Access Control Lists (ACLs) to access restricted functionality. The attack is reachable over the network without user interaction. Successful exploitation grants the attacker full control over the confidentiality, integrity, and availability of the affected system.

Affected products

  • Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage through 31012025

Timeline

  • 2025-11-20: advisory: Initial disclosure by TR-CERT/USOM

References

Related threats