CVE-2018-25223

CRITICAL

Crashmail 1.6 Stack-based Buffer Overflow Remote Code Execution

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25223. PoCs published by Juan Sacco.

AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in Crashmail 1.6, leveraging a ROP chain to execute arbitrary code (specifically, spawning a shell via execve). The payload is crafted to overwrite the return address and construct a ROP chain using gadgets from the statically linked binary.

Description

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.

Exploits (1)

exploitdb WORKING POC
by Juan Sacco · pythonlocallinux
https://www.exploit-db.com/exploits/44331

This exploit demonstrates a stack-based buffer overflow in Crashmail 1.6, leveraging a ROP chain to execute arbitrary code (specifically, spawning a shell via execve). The payload is crafted to overwrite the return address and construct a ROP chain using gadgets from the statically linked binary.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Crashmail 1.6
No auth needed
Prerequisites: Crashmail 1.6 installed on the target system · Ability to pass crafted input to the SETTINGS command
devstral-2 · analyzed Apr 08, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-44331
https://www.exploit-db.com/exploits/44331
Product product
Official Product Homepage
http://ftnapps.sourceforge.net/crashmail.html
Product product
Official Product Homepage
http://exploitpack.com
Third Party Advisory third-party-advisory
VulnCheck Advisory: Crashmail 1.6 Stack-based Buffer Overflow Remote Code Execution
https://www.vulncheck.com/advisories/crashmail-stack-based-buffer-overflow-remote-code-execution

Scores

CVSS v3 9.8
EPSS 0.0088
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-787
Status published
Products (2)
crashmail/Crashmail 1.6
ftnapps/crashmail_ii < 1.6
Published Mar 28, 2026
Tracked Since Mar 29, 2026