VYPR
Unrated severityNVD Advisory· Published Feb 20, 2026· Updated Apr 7, 2026

Sricam DeviceViewer 3.12.0.1 Local Buffer Overflow DEP Bypass

CVE-2019-25435

Description

Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the Username field in User Management to trigger a stack-based buffer overflow and execute commands via ROP chain gadgets.

Affected products

1
  • Sricam/Sricam DeviceViewerv5
    Range: 3.12.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.