CVE-2019-25435

S

ricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the Username field in User Management to trigger a stack-based buffer overflow and execute commands via ROP chain gadgets.

Configurations

Configuration 1 (hide)

cpe:2.3:a:sricam:deviceviewer:3.12.0.1:*:*:*:*:-:*:*

History

26 Feb 2026, 02:33

Type Values Removed Values Added
First Time Sricam deviceviewer
Sricam
CPE cpe:2.3:a:sricam:deviceviewer:3.12.0.1:*:*:*:*:-:*:*
References () https://www.exploit-db.com/exploits/47477 - () https://www.exploit-db.com/exploits/47477 - Exploit, VDB Entry
References () https://www.sricam.com/ - () https://www.sricam.com/ - Product
References () https://www.vulncheck.com/advisories/sricam-deviceviewer-local-buffer-overflow-dep-bypass - () https://www.vulncheck.com/advisories/sricam-deviceviewer-local-buffer-overflow-dep-bypass - Third Party Advisory
Summary
  • (es) Sricam DeviceViewer 3.12.0.1 contiene una vulnerabilidad de desbordamiento de búfer local en la función de añadir usuario de la gestión de usuarios que permite a atacantes autenticados ejecutar código arbitrario evadiendo la prevención de ejecución de datos. Los atacantes pueden inyectar una carga útil maliciosa a través del campo Nombre de usuario en Gestión de usuarios para desencadenar un desbordamiento de búfer basado en pila y ejecutar comandos a través de gadgets de cadena ROP.

20 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 23:16

Updated : 2026-02-26 02:33


NVD link : CVE-2019-25435

Mitre link : CVE-2019-25435

CVE.ORG link : CVE-2019-25435


JSON object : View

Products Affected
CWE
CWE-121

Stack-based Buffer Overflow