CVE-2025-34119 is a remote file disclosure vulnerability in EasyCafe Server 2.2.14. The server exposes a custom protocol on TCP port 831 and processes requests using protocol opcodes. The flaw is in handling opcode 0x43, which can be used to request files by absolute path. The server does not enforce authentication or adequate authorization checks before servicing the request. As a result, an unauthenticated remote attacker can supply an arbitrary absolute file path and, if the targeted file exists and is readable by the server process, the server returns the file contents. This enables disclosure of sensitive local files, including operating system configuration files, password files, and application data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit auxiliary module that exploits a file retrieval vulnerability (CVE-2025-34119) in EasyCafe Server version 2.2.14 on Windows XP SP3 and Windows 7 SP1. The exploit works by sending a specially crafted TCP packet (opcode 0x43) to port 831 of the target server, specifying a file path (up to 67 characters, MS-DOS 8.3 format may be required). If the file exists, the server responds with its contents, which the module saves locally. The module is operational and allows arbitrary file read access on the vulnerable server. The only code file is a Ruby script structured as a Metasploit module, with clear options for target port and file path. No detection or fake code is present; the module is a functional exploit for remote file access.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.