CVE-2025-34046
An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly v...
Affects 0 products across 3 vendors.
Application allows file uploads without validating type, enabling upload of executable code or web shells.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface, allowing attackers to upload arbitrary files via the /general/index/UploadFile.php endpoint.
BSID: BS-2025-GLOBAL-254831-I • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-34046?
Is CVE-2025-34046 actively exploited?
How do I remediate CVE-2025-34046?
What systems are affected by CVE-2025-34046?
| CVE ID | CVE-2025-34046 |
|---|---|
| BSID | BS-2025-GLOBAL-254831-I BreachSpider Global ID |
| Published | 2025-06-26 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with certain parameters (uploadType=eoffice_logo or uploadType=theme). An attacker can exploit this flaw by sending a crafted HTTP POST request to upload arbitrary files without requiring authentication. Successful exploitation could enable remote code execution on the affected server, leading to complete compromise of the web application and potentially the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
Source: NIST NVD / MITRE CVE Database
The vulnerability is triggered by sending a crafted HTTP POST request to the /general/index/UploadFile.php endpoint with specific parameters (uploadType=eoffice_logo or uploadType=theme). The endpoint improperly validates the uploaded files, enabling an attacker to upload malicious files without authentication.
Exploitation Likelihood: HIGH
| Vendor | Product | Fixed Version |
|---|---|---|
| E-Office | — | — |
| Files | — | — |
| Foundation | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 766be51ec5ea199fd273dd4778625c37d3fa33a7b6d53a94438c347c7da578100392b9ba6b97baa81784cd5ffbe910deeb6b5e54668b0bc4a2b12f4e12f26485 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →