CVE-2025-34046

N/A

An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly v...

Affects 0 products across 3 vendors.

BCS4.78
CVSS v410.0
EPSS0.8%
Percentile52th
PatchUnknown
CWE Weakness Definitions
CWE-434: Unrestricted Upload of File with Dangerous Type

Application allows file uploads without validating type, enabling upload of executable code or web shells.

Related Attack Patterns (CAPEC)
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
via CWE-434

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface, allowing attackers to upload arbitrary files via the /general/index/UploadFile.php endpoint.

BSID: BS-2025-GLOBAL-254831-I • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-34046?
An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface, allowing attackers to upload arbitrary files via the /general/index/UploadFile.php endpoint.
Is CVE-2025-34046 actively exploited?
No confirmed active exploitation of CVE-2025-34046 as of 2026-05-30.
How do I remediate CVE-2025-34046?
Priority: IMMEDIATE.
What systems are affected by CVE-2025-34046?
CVE-2025-34046 affects: E-Office, Files, Foundation.
Vulnerability Details
CVE IDCVE-2025-34046
BSIDBS-2025-GLOBAL-254831-I BreachSpider Global ID
Published2025-06-26
Last Modified2026-04-15
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with certain parameters (uploadType=eoffice_logo or uploadType=theme). An attacker can exploit this flaw by sending a crafted HTTP POST request to upload arbitrary files without requiring authentication. Successful exploitation could enable remote code execution on the affected server, leading to complete compromise of the web application and potentially the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is triggered by sending a crafted HTTP POST request to the /general/index/UploadFile.php endpoint with specific parameters (uploadType=eoffice_logo or uploadType=theme). The endpoint improperly validates the uploaded files, enabling an attacker to upload malicious files without authentication.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
E-Office &mdash;
Files &mdash;
Foundation &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 394 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash766be51ec5ea199fd273dd4778625c37d3fa33a7b6d53a94438c347c7da578100392b9ba6b97baa81784cd5ffbe910deeb6b5e54668b0bc4a2b12f4e12f26485
Related CVEs affecting E-Office
CVE-2023-2523 9.8 A vulnerability was found in Weaver E-Office 9.5. It has been rated as critic... CVE-2022-50993 9.8 Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthent...
View all E-Office CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →