CVE-2019-25357
Severity CVSS v4.0:
HIGH
Type:
CWE-121
Stack-based Buffer Overflow
Publication date:
18/02/2026
Last modified:
18/02/2026
Description
Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious payload exceeding 664 bytes to inject shellcode and potentially execute arbitrary code on vulnerable Windows systems.
Impact
Base Score 4.0
8.40
Severity 4.0
HIGH
Base Score 3.x
8.40
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- http://www.webgateinc.com/wgi/eng/products/list.php?ec_idx1=P610
- http://www.webgateinc.com/wgi/eng/products/list.php?ec_idx1=P610&ptype=view&page=&p_idx=90&tab=download#tabdown
- https://www.exploit-db.com/exploits/47645
- https://www.vulncheck.com/advisories/control-center-pro-local-stack-based-bufferoverflow



