CVE-2025-34046: Fanwei E-Office Unauthenticated File Upload

Published Jun 26, 2025
·
Updated

An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with certain parameters (uploadType=eofficelogo or uploadType=theme). An attacker can exploit this flaw by sending a crafted HTTP POST request to upload arbitrary files without requiring authentication. Successful exploitation could enable remote code execution on the affected server, leading to complete compromise of the web application and potentially the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

Affected Software

1 affected component
Fanwei E-Office<=9.4

Event History

Jun 26, 2025
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-34046?

CVE-2025-34046 is classified as a critical vulnerability due to its potential for unauthorized file uploads.

2

How do I fix CVE-2025-34046?

To fix CVE-2025-34046, update the Fanwei E-Office software to a version beyond 9.4 that has addressed this vulnerability.

3

What impact does CVE-2025-34046 have on my systems?

CVE-2025-34046 allows attackers to upload malicious files, potentially leading to further exploitation or unauthorized access.

4

Is CVE-2025-34046 exploitable remotely?

Yes, CVE-2025-34046 can be exploited remotely since it affects an unauthenticated web management interface.

5

What versions of Fanwei E-Office are affected by CVE-2025-34046?

CVE-2025-34046 affects all versions of Fanwei E-Office up to and including version 9.4.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203