CVE-2025-34119
A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server listens for a custom protocol where opcode 0x43 can be used to request arbitrary files by absolute path. If the file exists and is accessible, its content is returned without authentication. This flaw allows attackers to retrieve sensitive files such as system configuration, password files, or application data.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 2.17%
- CWE
- CWE-668, CWE-306
- Published
- 2025-07-16
- Last modified
- 2026-04-07
Affected products
- Tinasoft EasyCafe Server
Weakness type
Related vulnerabilities
- CVE-2026-85053 — Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote...
- CVE-2026-82652 — SiYuan before v3.8.1 Information Disclosure via Publish Access
- CVE-2026-82650 — SiYuan before v3.8.1 Path Traversal via /api/template/render
- CVE-2026-72924 — GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
- CVE-2026-79068 — Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote...
- CVE-2026-79031 — Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote...
- CVE-2026-59308 — Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation
- CVE-2026-73843 — OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs