Impact
A remote file disclosure vulnerability is present in EasyCafe Server 2.2.14 that allows an unauthenticated attacker to retrieve arbitrary files by sending opcode 0x43 over TCP port 831. The server responds with the requested file contents if the file is accessible, exposing sensitive data such as configuration files, passwords, or application data. The flaw does not grant code execution or privilege escalation, but it enables significant confidentiality loss.
Affected Systems
The affected product is Tinasoft EasyCafe Server version 2.2.14. No other versions were listed.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, and an EPSS score of 30% reflects a high probability that the exploit is being used in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers can trigger the flaw from any network location that can reach TCP port 831, without authentication or additional access rights, making it readily exploitable.
OpenCVE Enrichment
EUVD