CVE-2018-25221
CRITICALEChat Server 3.1 Buffer Overflow via chat.ghp username Parameter
Title source: cnaDescription
EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code execution in the application context.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0010
EPSS Percentile
27.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (2)
echatserver/easy_chat_server
< 3.1
Echatserver/EChat Server
3.1
Published
Mar 28, 2026
Tracked Since
Mar 29, 2026