CVE-2018-25235
Severity CVSS v4.0:
MEDIUM
Type:
CWE-787
Out-of-bounds Write
Publication date:
30/03/2026
Last modified:
08/04/2026
Description
NetworkActiv Web Server 4.0 contains a buffer overflow vulnerability in the username field of the Security options that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by entering a crafted username value exceeding the expected buffer size through the Set username interface.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
6.20
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:networkactiv:web_server:*:*:*:*:*:*:*:* | 4.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



