Junglewise Threat Intelligence

CVE-2025-15070: Gmission Web Fax missing authorization in authentication module

CVE-2025-15070 · Severity: medium · CVSS 5.5 · Published 2025-12-29

Executive brief

Gmission Web Fax, a digital faxing solution, contains a security vulnerability that could allow unauthorized access to sensitive information. An attacker with basic access to the system could bypass authorization checks to view data they are not permitted to see. This could lead to the exposure of private fax communications or other confidential administrative information.

Technical details

Gmission Web Fax versions 3.0 prior to 3.0.1 are vulnerable to CWE-862 (Missing Authorization) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The flaw allows an authenticated user with low privileges to bypass authorization mechanisms and access sensitive data or abuse authentication functions. While some assessments suggest a network attack vector, the primary CNA reporting indicates a local attack vector (AV:L) requiring low privileges (PR:L). The vulnerability was addressed in version 3.0.1.

Affected products

  • Gmission Web Fax from 3.0 before 3.0.1

Timeline

  • 2025-12-29: advisory: Initial publication of CVE-2025-15070

References

Related threats