PT-2026-27360 · Flexhex+1 · River Past Cam Do

Chris Au

·

Published

2026-03-24

·

Updated

2026-04-27

·

CVE-2019-25626

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions River Past Cam Do version 3.7.6
Description A local buffer overflow exists in the activation code input field. A local attacker can execute arbitrary code by providing a malicious activation code string. This is achieved by crafting a buffer with 608 bytes of junk data, followed by shellcode and SEH (Structured Exception Handling) chain overwrite values, which triggers code execution during the processing of the input in the activation dialog.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2019-25626

Affected Products

River Past Cam Do