CVE-2025-0645
7.2Narkom Communication and Software Technologies Trade Ltd. Co. · Pyxis Signage
A file upload vulnerability in Pyxis Signage allows attackers with high privileges to upload dangerous file types and bypass access control lists.
Executive summary
An unrestricted file upload vulnerability in Narkom Communication Pyxis Signage allows authenticated administrative users to compromise system integrity and execute arbitrary code.
Vulnerability
This flaw stems from an unrestricted upload of files with dangerous types (CWE-434), which permits an attacker with high privileges (PR:H) to bypass access control constraints and potentially achieve full system compromise.
Business impact
The ability to upload arbitrary files to the server poses a severe threat to business operations, as it can lead to remote code execution and full system takeover. Given the CVSS score of 7.2, this vulnerability represents a high risk to data confidentiality, integrity, and availability, potentially resulting in unauthorized access to sensitive corporate signage content or underlying infrastructure.
Remediation
Immediate Action: Contact Narkom Communication and Software Technologies Trade Ltd. Co. support to obtain the necessary security updates, as no public patch version is currently listed.
Proactive Monitoring: Review web server access logs for unusual file upload requests or the presence of unexpected executable files within the application directory.
Compensating Controls: Implement a Web Application Firewall (WAF) with strict file extension filtering and content inspection to block malicious payloads before they reach the application.
Exploitation status
Public Exploit Available: No — exploit_available (false)
Analyst recommendation
The severity of this vulnerability necessitates immediate attention from IT security teams responsible for managing Pyxis Signage deployments. While an official patch is pending or requires vendor coordination, administrators should restrict administrative access to the platform and implement strict egress and ingress filtering to prevent the execution of unauthorized files.
More Narkom Communication and Software Technologies Trade Ltd. Co. CVEs
Sources
Originally found and disclosed by Tunahan TEKEOĞLU, per the CVE Program record.