CVE-2025-34105

A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vulnerability arises from improper bounds checking on the path component of HTTP GET requests. By sending a specially crafted long URI, a remote unauthenticated attacker can trigger a buffer overflow, potentially leading to arbitrary code execution with SYSTEM privileges on vulnerable Windows hosts.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de desbordamiento de búfer en la pila de la interfaz web integrada de DiskBoss Enterprise, versiones 7.4.28, 7.5.12 y 8.2.14. Esta vulnerabilidad se debe a una comprobación incorrecta de los límites en el componente de ruta de las solicitudes HTTP GET. Al enviar una URL larga especialmente manipulada, un atacante remoto no autenticado puede provocar un desbordamiento de búfer, lo que podría provocar la ejecución de código arbitrario con privilegios de sistema en hosts Windows vulnerables.

15 Jul 2025, 14:15

Type Values Removed Values Added
References
  • {'url': 'https://vulncheck/advisories/diskboss-enterprise-buffer-overflow-rce', 'source': 'disclosure@vulncheck.com'}
  • () https://www.vulncheck.com/advisories/diskboss-enterprise-buffer-overflow-rce -

15 Jul 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-15 13:15

Updated : 2026-06-17 09:13


NVD link : CVE-2025-34105

Mitre link : CVE-2025-34105

CVE.ORG link : CVE-2025-34105


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-787

Out-of-bounds Write