CVE-2025-34046: Fanwei E-Office Unauthenticated File Upload
An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with certain parameters (uploadType=eofficelogo or uploadType=theme). An attacker can exploit this flaw by sending a crafted HTTP POST request to upload arbitrary files without requiring authentication. Successful exploitation could enable remote code execution on the affected server, leading to complete compromise of the web application and potentially the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34046?
CVE-2025-34046 is classified as a critical vulnerability due to its potential for unauthorized file uploads.
How do I fix CVE-2025-34046?
To fix CVE-2025-34046, update the Fanwei E-Office software to a version beyond 9.4 that has addressed this vulnerability.
What impact does CVE-2025-34046 have on my systems?
CVE-2025-34046 allows attackers to upload malicious files, potentially leading to further exploitation or unauthorized access.
Is CVE-2025-34046 exploitable remotely?
Yes, CVE-2025-34046 can be exploited remotely since it affects an unauthenticated web management interface.
What versions of Fanwei E-Office are affected by CVE-2025-34046?
CVE-2025-34046 affects all versions of Fanwei E-Office up to and including version 9.4.