CVE-2019-25436

MEDIUM

Sricam DeviceViewer 3.12.0.1 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25436. PoCs published by Alessandro Magnosi.

AI-analyzed exploit summary This exploit demonstrates an arbitrary password change vulnerability in DeviceViewer 3.12.0.1 by leveraging a buffer overflow in the password change functionality. The PoC generates a malicious payload file that, when used as the 'old password,' bypasses authentication and allows setting a new password.

Description

Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old password field. Attackers can inject a large payload into the old password parameter during the change password process to bypass validation and set an arbitrary new password.

Exploits (1)

exploitdb WORKING POC
by Alessandro Magnosi · pythonlocalwindows
https://www.exploit-db.com/exploits/47476

This exploit demonstrates an arbitrary password change vulnerability in DeviceViewer 3.12.0.1 by leveraging a buffer overflow in the password change functionality. The PoC generates a malicious payload file that, when used as the 'old password,' bypasses authentication and allows setting a new password.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: DeviceViewer v3.12.0.1
Auth required
Prerequisites: Access to a registered user account · Ability to execute the script and interact with the application
devstral-2 · analyzed Feb 21, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/47476
Various Sources product
http://www.sricam.com/

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 15.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-303
Status published
Products (2)
sricam/deviceviewer 3.12.0.1
Sricam/DeviceViewer 3.12.0.1
Published Feb 20, 2026
Tracked Since Feb 21, 2026