CVE-2019-25626

Severity CVSS v4.0:
HIGH
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
24/03/2026
Last modified:
27/04/2026

Description

River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows local attackers to execute arbitrary code by supplying a malicious activation code string. Attackers can craft a buffer containing 608 bytes of junk data followed by shellcode and SEH chain overwrite values to trigger code execution when the activation dialog processes the input.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:river_past_cam_do_project:river_past_cam_do:*:*:*:*:*:*:*:* 3.7.6 (including)