PT-2026-26978 · Labf · Axessh

Victor Mondragón

·

Published

2026-03-22

·

Updated

2026-03-22

·

CVE-2019-25590

CVSS v3.1

6.2

Medium

AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Axessh 4.2 contains a denial of service vulnerability in the logging configuration that allows local attackers to crash the application by supplying an excessively long string in the log file name field. Attackers can enable session logging, paste a buffer of 500 or more characters into the log file name parameter, and trigger a crash when establishing a telnet connection.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2019-25590

Affected Products

Axessh