CVE Database
/

CVE-2025-34105

Back to search

CVE-2025-34105

Published: Jul 15, 2025

Modified: Apr 7, 2026

PUBLISHED

Description

A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vulnerability arises from improper bounds checking on the path component of HTTP GET requests. By sending a specially crafted long URI, a remote unauthenticated attacker can trigger a buffer overflow, potentially leading to arbitrary code execution with SYSTEM privileges on vulnerable Windows hosts.

VendorProductVersions

Flexense

DiskBoss Enterprise

affected
7.4.28
affected
7.5.12
affected
8.2.14

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now