Official Product Homepageproduct
http://www.speedbit.com/dap CVE-2019-25628
CRITICAL
Download Accelerator Plus DAP 10.0.6.0 SEH Buffer Overflow
Record summary
CVE-2019-25628 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. Attackers can create specially crafted URLs with overflowing buffer data that overwrites SEH pointers and executes embedded shellcode when imported through the application's web page import functionality.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Download Accelerator Plus DAPBrowse Speedbit / Download Accelerator Plus DAP | CVE List | 10.0.6.0 # | affected |
Proofs of concept
1Catalogued exploits
ExploitDBDownload Accelerator Plus (DAP) 10.0.6.0 - SEH Buffer OverflowExploitDB exploitby Peyman ForouzanNot analyzed1 file
References
5Product Referenceproduct
http://www.speedbit.com/dap/download/downloading.asp nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25628 ExploitDB-46673exploit
https://www.exploit-db.com/exploits/46673 VulnCheck Advisory: Download Accelerator Plus DAP 10.0.6.0 SEH Buffer OverflowThird-party advisory
https://www.vulncheck.com/advisories/download-accelerator-plus-dap-seh-buffer-overflow