Unrated severityNVD Advisory· Published Feb 20, 2026· Updated Apr 7, 2026
Sricam DeviceViewer 3.12.0.1 Local Buffer Overflow DEP Bypass
CVE-2019-25435
Description
Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the Username field in User Management to trigger a stack-based buffer overflow and execute commands via ROP chain gadgets.
Affected products
1- Sricam/Sricam DeviceViewerv5Range: 3.12.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/47477mitreexploit
- www.vulncheck.com/advisories/sricam-deviceviewer-local-buffer-overflow-dep-bypassmitrethird-party-advisory
- www.sricam.commitreproduct
News mentions
0No linked articles in our index yet.