Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary system files through the server.copyfile API endpoint. Attackers can exploit the vulnerability by supplying crafted parameters to download sensitive files like /etc/passwd using curl and wget requests.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centova Technologies Inc.
Centova Technologies Inc. centova Cast |
|
| Vendors & Products |
Centova Technologies Inc.
Centova Technologies Inc. centova Cast |
Wed, 18 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary system files through the server.copyfile API endpoint. Attackers can exploit the vulnerability by supplying crafted parameters to download sensitive files like /etc/passwd using curl and wget requests. | |
| Title | Centova Cast 3.2.11 - Arbitrary File Download | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-18T21:54:57.670Z
Reserved: 2026-02-13T17:28:51.148Z
Link: CVE-2019-25351
No data.
Status : Received
Published: 2026-02-18T22:16:19.933
Modified: 2026-02-18T22:16:19.933
Link: CVE-2019-25351
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:10:51Z