PT-2026-27360 · Flexhex · River Past Cam Do

Chris Au

·

Published

2026-03-24

·

Updated

2026-03-24

·

CVE-2019-25626

CVSS v3.1

8.4

High

AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows local attackers to execute arbitrary code by supplying a malicious activation code string. Attackers can craft a buffer containing 608 bytes of junk data followed by shellcode and SEH chain overwrite values to trigger code execution when the activation dialog processes the input.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2019-25626

Affected Products

River Past Cam Do