Lyrie
Critical CVE
CVSS 9.93 sources verified·1 min read
By Lyrie Threat Intelligence·5/26/2026

CRITICAL: CVE-2025-1782 (CVSS 9.9) — multiple products

CVE: CVE-2025-1782

CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Severity: CRITICAL

Status: Critical advisory

Affected

_See vendor advisory_

Summary

In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized

before being used and can be misused to include an arbitrary file in the

PHP code allowing an attacker to do anything as the web server user.

This flaw requires the attacker to be authenticated with a valid user account.

Verified Sources

References

  • https://www.ifax.com/security/CVE-2025-1782.html

_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._

Lyrie Verdict

A vulnerability of this severity is exactly what Lyrie's anti-rogue-AI defense is built for: continuous, autonomous monitoring that doesn't wait for human reaction time.

Validated sources

  1. [1]NVD
  2. [2]GitHub Advisory
  3. [3]MITRE