CVE-2025-0645

7.2

Narkom Communication and Software Technologies Trade Ltd. Co. · Pyxis Signage

A file upload vulnerability in Pyxis Signage allows attackers with high privileges to upload dangerous file types and bypass access control lists.

Executive summary

An unrestricted file upload vulnerability in Narkom Communication Pyxis Signage allows authenticated administrative users to compromise system integrity and execute arbitrary code.

Vulnerability

This flaw stems from an unrestricted upload of files with dangerous types (CWE-434), which permits an attacker with high privileges (PR:H) to bypass access control constraints and potentially achieve full system compromise.

Business impact

The ability to upload arbitrary files to the server poses a severe threat to business operations, as it can lead to remote code execution and full system takeover. Given the CVSS score of 7.2, this vulnerability represents a high risk to data confidentiality, integrity, and availability, potentially resulting in unauthorized access to sensitive corporate signage content or underlying infrastructure.

Remediation

Immediate Action: Contact Narkom Communication and Software Technologies Trade Ltd. Co. support to obtain the necessary security updates, as no public patch version is currently listed.

Proactive Monitoring: Review web server access logs for unusual file upload requests or the presence of unexpected executable files within the application directory.

Compensating Controls: Implement a Web Application Firewall (WAF) with strict file extension filtering and content inspection to block malicious payloads before they reach the application.

Exploitation status

Public Exploit Available: No — exploit_available (false)

Analyst recommendation

The severity of this vulnerability necessitates immediate attention from IT security teams responsible for managing Pyxis Signage deployments. While an official patch is pending or requires vendor coordination, administrators should restrict administrative access to the platform and implement strict egress and ingress filtering to prevent the execution of unauthorized files.

More Narkom Communication and Software Technologies Trade Ltd. Co. CVEs

Sources

Originally found and disclosed by Tunahan TEKEOĞLU, per the CVE Program record.