Softros LAN Messenger 9.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the custom log files location field. Attackers can input a buffer of 2000 characters in the Log Files Location custom path parameter to trigger a crash when the OK button is clicked.
References
| Link | Resource |
|---|---|
| https://messenger.softros.com/ | Product |
| https://messenger.softros.com/downloads/ | Product |
| https://www.exploit-db.com/exploits/45781 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/softros-lan-messenger-denial-of-service-via-log-files-location | Third Party Advisory |
Configurations
History
08 Apr 2026, 16:54
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:softros:softros_lan_messenger:*:*:*:*:*:*:*:* | |
| First Time |
Softros softros Lan Messenger
Softros |
|
| Summary |
|
|
| References | () https://messenger.softros.com/ - Product | |
| References | () https://messenger.softros.com/downloads/ - Product | |
| References | () https://www.exploit-db.com/exploits/45781 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/softros-lan-messenger-denial-of-service-via-log-files-location - Third Party Advisory |
30 Mar 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-30 12:16
Updated : 2026-04-08 16:54
NVD link : CVE-2018-25232
Mitre link : CVE-2018-25232
CVE.ORG link : CVE-2018-25232
JSON object : View
Products Affected
softros
- softros_lan_messenger
CWE
CWE-1285
Improper Validation of Specified Index, Position, or Offset in Input
