CVE-2025-34108

A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. An attacker can send a specially crafted HTTP POST request to the /login endpoint with an overly long username parameter, causing a buffer overflow in the libspp.dll component. Successful exploitation allows arbitrary code execution with SYSTEM privileges.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Jul 2025, 20:07

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-15 13:15

Updated : 2025-07-15 20:07


NVD link : CVE-2025-34108

Mitre link : CVE-2025-34108

CVE.ORG link : CVE-2025-34108


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-121

Stack-based Buffer Overflow