PT-2026-29019 · Southrivertech · Webdrive

Published

2026-03-30

·

Updated

2026-04-08

·

CVE-2018-25233

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions WebDrive version 18.00.5057
Description WebDrive 18.00.5057 contains a denial of service issue that allows local attackers to crash the application. This occurs by providing an excessively long string in the username field during Secure WebDAV connection setup. Attackers can input a buffer overflow payload of 5000 bytes in the username parameter and trigger a connection test to cause the application to crash.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, limit the length of the username input field during Secure WebDAV connection setup.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2018-25233

Affected Products

Webdrive