Executive brief
Gmission Web Fax, a digital faxing solution, contains a security vulnerability that allows for the unauthorized upload of dangerous files. An attacker could exploit this to execute malicious code on the system, potentially leading to a full system takeover, data theft, or service disruption. This issue affects versions 3.0 through 3.1 of the software.
Technical details
Gmission Web Fax (versions 3.0 to 3.1) suffers from a vulnerability involving improper input validation (CWE-20) and unrestricted upload of files with dangerous types (CWE-434). The flaw allows an attacker to perform Remote Code Inclusion (RCI) by uploading malicious files to the server. While the CVSS vector (AV:L) suggests a local attack vector, the nature of the 'Web Fax' component typically implies a network-accessible interface; however, based strictly on the provided metadata, the attack is classified as local. Successful exploitation grants the attacker the ability to execute arbitrary code with the privileges of the web service, compromising confidentiality, integrity, and availability.
Affected products
- Gmission Web Fax 3.0 to 3.1
Timeline
- 2026-05-21: advisory: NVD publication date