CVE-2019-25637

HIGH

X-NetStat Pro 5.63 Local Buffer Overflow via EggHunter

Title source: cna
STIX 2.1

Description

X-NetStat Pro 5.63 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the EIP register through a 264-byte buffer overflow. Attackers can inject shellcode into memory and use an egg hunter technique to locate and execute the payload when the application processes malicious input through HTTP Client or Rules functionality.

Exploits (1)

exploitdb WORKING POC
by Peyman Forouzan · pythonlocalwindows
https://www.exploit-db.com/exploits/46596

Scores

CVSS v3 8.4
EPSS 0.0002
EPSS Percentile 5.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (1)
Freshsoftware/NetStat Pro 5.63 #
Published Mar 24, 2026
Tracked Since Mar 24, 2026