CVE-2025-34046 Details
Description
An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with certain parameters (uploadType=eoffice_logo or uploadType=theme). An attacker can exploit this flaw by sending a crafted HTTP POST request to upload arbitrary files without requiring authentication. Successful exploitation could enable remote code execution on the affected server, leading to complete compromise of the web application and potentially the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
A file upload vulnerability allowing for remote code execution has been identified in the Fanwei E-Office web management interface, specifically in versions through 9.4. The issue arises in the UploadFile.php endpoint, which fails to properly validate uploaded files when certain parameters are used. An attacker can exploit this vulnerability by sending a crafted HTTP POST request to upload arbitrary files without authentication. Successful exploitation could lead to a complete compromise of the web application and potentially the underlying system.
Users are advised to update to the latest version of Fanwei E-Office, as the vendor has released a patch for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 26, 2025CISA-ADP
Assessed Jun 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Fanwei E-Office | <= 9.4 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 20, 2025 | CVE Modified | [email protected] |
| Nov 17, 2025 | CVE Modified | [email protected] |
| Nov 17, 2025 | CVE Modified | [email protected] |
| Jun 26, 2025 | New CVE Received | [email protected] |
Volerion