CVE-2019-25435

Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the Username field in User Management to trigger a stack-based buffer overflow and execute commands via ROP chain gadgets.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sricam:deviceviewer:3.12.0.1:*:*:*:*:-:*:*

History

26 Feb 2026, 02:33

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/47477 - () https://www.exploit-db.com/exploits/47477 - Exploit, VDB Entry
References () https://www.sricam.com/ - () https://www.sricam.com/ - Product
References () https://www.vulncheck.com/advisories/sricam-deviceviewer-local-buffer-overflow-dep-bypass - () https://www.vulncheck.com/advisories/sricam-deviceviewer-local-buffer-overflow-dep-bypass - Third Party Advisory
CPE cpe:2.3:a:sricam:deviceviewer:3.12.0.1:*:*:*:*:-:*:*
Summary
  • (es) Sricam DeviceViewer 3.12.0.1 contiene una vulnerabilidad de desbordamiento de búfer local en la función de añadir usuario de la gestión de usuarios que permite a atacantes autenticados ejecutar código arbitrario evadiendo la prevención de ejecución de datos. Los atacantes pueden inyectar una carga útil maliciosa a través del campo Nombre de usuario en Gestión de usuarios para desencadenar un desbordamiento de búfer basado en pila y ejecutar comandos a través de gadgets de cadena ROP.
First Time Sricam deviceviewer
Sricam

20 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 23:16

Updated : 2026-02-26 02:33


NVD link : CVE-2019-25435

Mitre link : CVE-2019-25435

CVE.ORG link : CVE-2019-25435


JSON object : View

Products Affected

sricam

  • deviceviewer
CWE
CWE-121

Stack-based Buffer Overflow