Record summary

CVE-2019-25628 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. Attackers can create specially crafted URLs with overflowing buffer data that overwrites SEH pointers and executes embedded shellcode when imported through the application's web page import functionality.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List10.0.6.0 #affected

Proofs of concept

1

Catalogued exploits

ExploitDBDownload Accelerator Plus (DAP) 10.0.6.0 - SEH Buffer OverflowExploitDB exploitby Peyman ForouzanNot analyzed1 file
ExploitDB

PoC details

References

5