Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary system files through the server.copyfile API endpoint. Attackers can exploit the vulnerability by supplying crafted parameters to download sensitive files like /etc/passwd using curl and wget requests.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centova Technologies Inc.
Centova Technologies Inc. centova Cast |
|
| Vendors & Products |
Centova Technologies Inc.
Centova Technologies Inc. centova Cast |
Wed, 18 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary system files through the server.copyfile API endpoint. Attackers can exploit the vulnerability by supplying crafted parameters to download sensitive files like /etc/passwd using curl and wget requests. | |
| Title | Centova Cast 3.2.11 - Arbitrary File Download | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-18T21:54:57.670Z
Updated: 2026-02-19T15:32:41.538Z
Reserved: 2026-02-13T17:28:51.148Z
Link: CVE-2019-25351
Updated: 2026-02-19T15:32:34.944Z
Status : Awaiting Analysis
Published: 2026-02-18T22:16:19.933
Modified: 2026-02-19T15:53:02.850
Link: CVE-2019-25351
No data.