CVE-2018-25278

MEDIUM

PicaJet FX 2.6.5 Denial of Service via Registration Fields

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25278. PoCs published by Gionathan Reale.

AI-analyzed exploit summary This Python script generates a 6000-byte buffer of 'A' characters to trigger a denial-of-service (DoS) in PicaJet FX 2.6.5 by overflowing input fields during registration. The exploit creates a file 'exploit.txt' which, when pasted into the 'Registration Name' or 'Registration Key' fields, causes the application to crash.

Description

PicaJet FX 2.6.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to registration fields. Attackers can paste a 6000-byte buffer into the Registration Name and Registration Key fields via the Help menu's Register PicaJet dialog to trigger an application crash.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Gionathan Reale · pythondoswindows_x86
https://www.exploit-db.com/exploits/45383

This Python script generates a 6000-byte buffer of 'A' characters to trigger a denial-of-service (DoS) in PicaJet FX 2.6.5 by overflowing input fields during registration. The exploit creates a file 'exploit.txt' which, when pasted into the 'Registration Name' or 'Registration Key' fields, causes the application to crash.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: PicaJet FX 2.6.5
No auth needed
Prerequisites: PicaJet FX 2.6.5 installed on Windows 7 32-bit · ability to paste content into registration fields
devstral-2 · analyzed Apr 26, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit
ExploitDB-45383
https://www.exploit-db.com/exploits/45383
Third Party Advisory third-party-advisory
VulnCheck Advisory: PicaJet FX 2.6.5 Denial of Service via Registration Fields
https://www.vulncheck.com/advisories/picajet-fx-denial-of-service-via-registration-fields

Scores

CVSS v3 6.2
EPSS 0.0014
EPSS Percentile 4.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (1)
Picajet/PicaJet FX 2.6.5
Published Apr 26, 2026
Tracked Since Apr 26, 2026