Record summary

CVE-2019-25351 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.

Description

Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary system files through the server.copyfile API endpoint. Attackers can exploit the vulnerability by supplying crafted parameters to download sensitive files like /etc/passwd using curl and wget requests.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 19, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List3.2.11affected

Proofs of concept

1

Catalogued exploits

ExploitDBCentova Cast 3.2.11 - Arbitrary File DownloadExploitDB exploitby DroidUNot analyzed1 file
ExploitDB

PoC details

References

4