Junglewise Threat Intelligence

CVE-2025-65418: docuFORM Managed Print Service Client directory traversal

CVE-2025-65418 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: docuForm Managed Print Service Client. Vendors: docuForm.

Executive brief

docuFORM Managed Print Service Client, a tool used to manage and monitor corporate printing and scanning infrastructure, is vulnerable to a security flaw that allows unauthorized access to files. By sending a specially crafted web request, an attacker can bypass security restrictions to read sensitive system files, configuration data, or application source code. This could lead to the exposure of proprietary information or credentials, potentially compromising the broader printing environment.

Technical details

A directory traversal vulnerability exists in docuFORM Managed Print Service Client (also referred to as FSM Client) version 11.11c. The flaw stems from insufficient validation and normalization of user-supplied input used to construct file paths. An unauthenticated remote attacker can exploit this by sending a crafted URL containing path traversal sequences (e.g., '../') to escape the application's intended web root. Successful exploitation allows the attacker to read sensitive files on the underlying filesystem, including configuration files and system data. While the NVD entry mentions directory traversal, the researcher's technical notes also categorize this as CWE-209 (Information Exposure Through an Error Message). A fix was reportedly published by the vendor in November 2025.

Affected products

  • docuFORM Managed Print Service Client (FSM Client) 11.11c

Timeline

  • 2025-10: other: Vulnerability reported to vendor
  • 2025-11: patched: Vendor published a fix
  • 2026-04: disclosed: Information about the vulnerability published by researcher
  • 2026-05-11: advisory: CVE published to NVD

References

Related threats