CVE-2015-2097

WebGate Embedded Standard Protocol SDK - Buffer Overflows in LoadImage, LoadImageEx, ChangePassword, Connect, and AddID

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2015-2097. PoCs published by Praveen Darshanam.

AI-analyzed exploit summary This exploit targets a stack buffer overflow in WebGate eDVR Manager's Connect method via a crafted HTML file. It uses a combination of NOP sleds, shellcode, and SEH overwrite to achieve remote code execution.

Description

Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3) ChangePassword function in the WESPCONFIGLib.UserItem control, Connect function in the (4) WESPSerialPort.WESPSerialPortCtrl.1 or (5) WESPPLAYBACKLib.WESPPlaybackCtrl control, or (6) AddID function in the WESPCONFIGLib.IDList control or a (7) long string to the second argument to the ConnectEx3 function in the WESPPLAYBACKLib.WESPPlaybackCtrl control.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Praveen Darshanam · htmlremotewindows
https://www.exploit-db.com/exploits/36607

This exploit targets a stack buffer overflow in WebGate eDVR Manager's Connect method via a crafted HTML file. It uses a combination of NOP sleds, shellcode, and SEH overwrite to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WebGate eDVR Manager (WESPSerialPort.dll)
No auth needed
Prerequisites: Victim must open the malicious HTML file in Internet Explorer 8 on Windows XP SP3
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Praveen Darshanam · htmlremotewindows
https://www.exploit-db.com/exploits/36602

This exploit targets a stack overflow vulnerability in WESP SDK's ChangePassword function via a maliciously crafted HTML file. It uses a combination of NOP sleds, shellcode, and SEH overwrites to achieve remote code execution on vulnerable systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WESP SDK (package version 1.2)
No auth needed
Prerequisites: Victim must open the malicious HTML file in a vulnerable browser (IE6/7/8) · WESP SDK (package version 1.2) must be installed on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Praveen Darshanam · textremotewindows
https://www.exploit-db.com/exploits/36505

This exploit targets a stack buffer overflow in WebGate eDVR Manager's WESPMonitor.WESPMonitorCtrl ActiveX control via the LoadImage method. It uses a crafted string to overwrite the SEH handler and execute shellcode for remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WebGate eDVR Manager WESPMonitor.WESPMonitorCtrl (Version 1.6.42.0)
No auth needed
Prerequisites: Target must have the vulnerable ActiveX control installed · Victim must visit a malicious webpage or open the exploit file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/118902
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/118893
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-15-059/
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/36607/
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/36505/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72835
Exploit exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/36602/
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-15-068/
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/118896
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-15-062/
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Feb/90

Scores

EPSS 0.2430
EPSS Percentile 97.6%

Details

CWE
CWE-119
Status published
Products (1)
webgate/webgate_embedded_standard_protocol_sdk
Published Mar 09, 2015
Tracked Since Feb 18, 2026