CVE-2025-15610Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed in environments where the remoting ports are accessible.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-15); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-15: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 104-1504-16
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-15610: OpenText, Inc (CVSS: 9.3)... RightFax's deserialization flaw screams RCE with zero auth required - fax servers are network-exposed goldmines waiting... https://zerodaysignal.com/vulnerability/CVE-2025-15610 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2025-15610, a deserialization-based RCE vulnerability in RightFax that requires no authentication, and includes a link to a vulnerability page detailing the flaw.

    00001227
    218 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15610 Deserialization of untrusted data vulnerability in OpenText, Inc RightFax on Windows, 64 bit, 32 bit allows Object Injection.This issue affects RightFax: through 25.4. https://www.cve.org/CVERecord?id=CVE-2025-15610

    Post summary

    The post announces CVE‑2025‑15610, describing a deserialization-based object injection flaw in RightFax with no mention of PoC, exploit code, active attacks, or remediation steps.

    00000188
    57.2K followersView on X

Explore more