PT-2026-26995 · Labf · Axessh
Uday Mittal
·
Published
2026-03-22
·
Updated
2026-03-22
·
CVE-2019-25607
CVSS v3.1
8.4
High
| AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Axessh 4.2 contains a stack-based buffer overflow vulnerability in the log file name field that allows local attackers to execute arbitrary code by supplying an excessively long filename. Attackers can overflow the buffer at offset 214 bytes to overwrite the instruction pointer and execute shellcode with system privileges.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Axessh