CVE-2013-0680

Cogent Real-Time Systems - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-0680. Includes Metasploit module exploits/windows/http/cogent_datahub_request_headers_bof.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in Cogent DataHub 7.3.0 via malformed HTTP headers, leveraging SEH overwrite for arbitrary code execution. It targets Windows XP SP3 with a reliable payload delivery mechanism.

Description

Stack-based buffer overflow in the web server in Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long HTTP header.

Exploits (1)

metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/cogent_datahub_request_headers_bof.rb

This Metasploit module exploits a stack-based buffer overflow in Cogent DataHub 7.3.0 via malformed HTTP headers, leveraging SEH overwrite for arbitrary code execution. It targets Windows XP SP3 with a reliable payload delivery mechanism.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cogent DataHub 7.3.0
No auth needed
Prerequisites: Network access to the target HTTP server · Cogent DataHub 7.3.0 running on Windows XP SP3
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
US Government Resource x_refsource_misc
http://ics-cert.us-cert.gov/pdf/ICSA-13-095-01.pdf

Scores

EPSS 0.1926
EPSS Percentile 97.0%

Details

CWE
CWE-119
Status published
Products (12)
cogentdatahub/cascade_datahub 6.4.20
cogentdatahub/cascade_datahub < 6.4.21
cogentdatahub/cogent_datahub 7.0
cogentdatahub/cogent_datahub 7.0.2
cogentdatahub/cogent_datahub 7.1.0
cogentdatahub/cogent_datahub 7.1.1
cogentdatahub/cogent_datahub 7.1.1.63
cogentdatahub/cogent_datahub 7.1.2
cogentdatahub/cogent_datahub < 7.2.2
cogentdatahub/datahub_quicktrend < 7.2.2
... and 2 more
Published Apr 05, 2013
Tracked Since Feb 18, 2026