CVE-2025-34046: CWE-434 Unrestricted Upload of File with Dangerous Type in Shanghai Fanwei Network Technology E-Office
An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with certain parameters (uploadType=eoffice_logo or uploadType=theme). An attacker can exploit this flaw by sending a crafted HTTP POST request to upload arbitrary files without requiring authentication. Successful exploitation could enable remote code execution on the affected server, leading to complete compromise of the web application and potentially the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
AI Analysis
Technical Summary
An unauthenticated file upload vulnerability (CWE-434) affects Shanghai Fanwei Network Technology E-Office version 0 at the /general/index/UploadFile.php endpoint when invoked with uploadType parameters 'eoffice_logo' or 'theme'. The endpoint improperly validates uploaded files, allowing attackers to send crafted HTTP POST requests to upload arbitrary files without authentication. Successful exploitation can lead to remote code execution on the affected server, resulting in complete compromise of the web application and potentially the underlying system. Exploitation evidence was observed by Shadowserver Foundation on 2025-02-05 UTC. The CVSS 4.0 base score is 10.0 (critical), reflecting network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, availability, and security requirements.
Potential Impact
The vulnerability enables unauthenticated attackers to upload arbitrary files to the affected server, which can be leveraged to execute remote code. This leads to full compromise of the E-Office web application and potentially the underlying operating system, allowing attackers to control the affected system completely.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is currently available. Until a patch is released, restrict access to the affected endpoint if possible and monitor for suspicious file upload activity.
CVE-2025-34046: CWE-434 Unrestricted Upload of File with Dangerous Type in Shanghai Fanwei Network Technology E-Office
Description
An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with certain parameters (uploadType=eoffice_logo or uploadType=theme). An attacker can exploit this flaw by sending a crafted HTTP POST request to upload arbitrary files without requiring authentication. Successful exploitation could enable remote code execution on the affected server, leading to complete compromise of the web application and potentially the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
CVSS v4.0
Score 10.0critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An unauthenticated file upload vulnerability (CWE-434) affects Shanghai Fanwei Network Technology E-Office version 0 at the /general/index/UploadFile.php endpoint when invoked with uploadType parameters 'eoffice_logo' or 'theme'. The endpoint improperly validates uploaded files, allowing attackers to send crafted HTTP POST requests to upload arbitrary files without authentication. Successful exploitation can lead to remote code execution on the affected server, resulting in complete compromise of the web application and potentially the underlying system. Exploitation evidence was observed by Shadowserver Foundation on 2025-02-05 UTC. The CVSS 4.0 base score is 10.0 (critical), reflecting network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, availability, and security requirements.
Potential Impact
The vulnerability enables unauthenticated attackers to upload arbitrary files to the affected server, which can be leveraged to execute remote code. This leads to full compromise of the E-Office web application and potentially the underlying operating system, allowing attackers to control the affected system completely.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is currently available. Until a patch is released, restrict access to the affected endpoint if possible and monitor for suspicious file upload activity.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2025-04-15T19:15:22.547Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 685d6fabca1063fb8742bc09
Added to database: 06/26/2025, 16:04:59 UTC
Last enriched: 07/15/2026, 09:50:17 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 599
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.