๐Ÿ” CVE Alert

CVE-2025-34119

UNKNOWN 0.0

EasyCafe Server 2.2.14 Remote File Disclosure via Opcode 0x43

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server listens for a custom protocol where opcode 0x43 can be used to request arbitrary files by absolute path. If the file exists and is accessible, its content is returned without authentication. This flaw allows attackers to retrieve sensitive files such as system configuration, password files, or application data.

CWE CWE-668 CWE-306
Vendor tinasoft
Product easycafe server
Published Jul 16, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for tinasoft easycafe server

Be the first to know when new unknown vulnerabilities affecting tinasoft easycafe server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Tinasoft / EasyCafe Server
2.2.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/scanner/misc/easycafe_server_fileaccess.rb exploit-db.com: https://www.exploit-db.com/exploits/39102 vulncheck.com: https://www.vulncheck.com/advisories/easy-cafe-server-remote-file-disclosure

Credits

R-73eN