CVE-2019-25326

Severity CVSS v4.0:
MEDIUM
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
18/02/2026
Last modified:
24/02/2026

Description

ipPulse 1.92 contains a denial of service vulnerability that allows local attackers to crash the application by providing an oversized input in the Enter Key field. Attackers can generate a 256-byte buffer of repeated 'A' characters to trigger an application crash when pasting the malicious content.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nwpsw:ippulse:*:*:*:*:*:*:*:* 1.92 (including)