Centova Cast Official Websiteproduct
https://centova.com/ CVE-2019-25351
HIGH
Centova Cast 3.2.11 - Arbitrary File Download
Record summary
CVE-2019-25351 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary system files through the server.copyfile API endpoint. Attackers can exploit the vulnerability by supplying crafted parameters to download sensitive files like /etc/passwd using curl and wget requests.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 19, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Centova CastBrowse Centova Technologies Inc. / Centova Cast | CVE List | 3.2.11 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCentova Cast 3.2.11 - Arbitrary File DownloadExploitDB exploitby DroidUNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25351 ExploitDB-47669exploit
https://www.exploit-db.com/exploits/47669 VulnCheck Advisory: Centova Cast 3.2.11 - Arbitrary File DownloadThird-party advisory
https://www.vulncheck.com/advisories/centova-cast-arbitrary-file-download