CVE-2018-25233

WebDrive 18.00.5057 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the username field during Secure WebDAV connection setup. Attackers can input a buffer-overflow payload of 5000 bytes in the username parameter and trigger a connection test to cause the application to crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:southrivertech:webdrive:18.00.5057:*:*:*:*:*:*:*

History

08 Apr 2026, 16:43

Type Values Removed Values Added
CPE cpe:2.3:a:southrivertech:webdrive:18.00.5057:*:*:*:*:*:*:*
First Time Southrivertech webdrive
Southrivertech
References () https://webdrive.com/ - () https://webdrive.com/ - Product
References () https://webdrive.com/download/ - () https://webdrive.com/download/ - Broken Link, Product
References () https://www.exploit-db.com/exploits/45761 - () https://www.exploit-db.com/exploits/45761 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/webdrive-denial-of-service-via-secure-webdav - () https://www.vulncheck.com/advisories/webdrive-denial-of-service-via-secure-webdav - Third Party Advisory
Summary
  • (es) WebDrive 18.00.5057 contiene una vulnerabilidad de denegación de servicio que permite a atacantes locales bloquear la aplicación al proporcionar una cadena excesivamente larga en el campo de nombre de usuario durante la configuración de una conexión Secure WebDAV. Los atacantes pueden introducir una carga útil de desbordamiento de búfer de 5000 bytes en el parámetro de nombre de usuario y activar una prueba de conexión para provocar el bloqueo de la aplicación.

30 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 12:16

Updated : 2026-04-08 16:43


NVD link : CVE-2018-25233

Mitre link : CVE-2018-25233

CVE.ORG link : CVE-2018-25233


JSON object : View

Products Affected

southrivertech

  • webdrive
CWE
CWE-233

Improper Handling of Parameters