PT-2026-46211 · Mobatek · Mobatek Mobaxterm

Xavi Beltran

·

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2019-25741

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. Attackers can craft a malicious MobaXterm sessions file with overflow data that triggers the vulnerability when imported and executed, enabling reverse shell execution with user privileges.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2019-25741

Affected Products

Mobatek Mobaxterm