CVE-2019-25232 Details
Description
NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attackers to execute arbitrary shellcode. Attackers can craft a malicious payload in the DNS/IP input to overwrite SEH handlers and execute shellcode when adding a new client.
A buffer overflow vulnerability has been identified in NetPCLinker version 1.0.0.0. The issue resides in the Clients Control Panel DNS/IP field, where improper input handling allows attackers to execute arbitrary shellcode. By crafting a malicious payload and overwriting Structured Exception Handling (SEH) handlers, attackers can execute their code when adding a new client.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 30, 2026CISA-ADP
Assessed Feb 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sourceforge.net/projects/netpclinker/ | [email protected] | ProductVendor |
| https://www.exploit-db.com/exploits/48680 | [email protected] | Exploit |
| https://www.vulncheck.com/advisories/netpclinker-buffer-overflow | [email protected] | AdvisoryBroken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NetPCLinker | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 30, 2026 | New CVE Received | [email protected] |
Volerion