CVE-2025-15610 Details
Description
The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed in environments where the remoting ports are accessible.
A deserialization vulnerability allowing object injection has been identified in OpenText RightFax versions through 25.4, on both 32-bit and 64-bit Windows systems. This vulnerability arises from the .NET Remoting framework, which contains known security flaws that could be exploited if the RightFax service is exposed and the remoting ports are accessible.
OpenText is developing patches for RightFax versions 16.6, 20.2, 21.2, 22.2, 23.4, 24.4, and 25.4, with a target release date by the end of April 2026. In the meantime, customers can block ports 34001 and 34002 at their firewall, although this may cause communication issues with IIS and Remote RightFax Web Services for versions 20.2 and later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0861863 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 15, 2026 | New CVE Received | [email protected] |