CVE-2025-34096 - CVE House
Back to Database
Status published Critical CVE-2025-34096

Easy File Sharing HTTP Server 7.2 Buffer Overflow via POST to /sendemail.ghp

Vulnerability Description

A stack-based buffer overflow vulnerability exists in Easy File Sharing HTTP Server version 7.2. The flaw is triggered when a crafted POST request is sent to the /sendemail.ghp endpoint containing an overly long Email parameter. The application fails to properly validate the length of this field, resulting in a memory corruption condition. An unauthenticated remote attacker can exploit this to execute arbitrary code with the privileges of the server process.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34096

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • bl4ck h4ck3r

Affected Vendor

EFS Software Inc.

View all reports →

Affected Software

Easy File Sharing HTTP Server
Vulnerable Versions:
7.2

Timeline

Official Publish: July 10th, 2025
Last Modified: April 7th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)