Back to search
CVE-2025-34108
Published: Jul 15, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. An attacker can send a specially crafted HTTP POST request to the /login endpoint with an overly long username parameter, causing a buffer overflow in the libspp.dll component. Successful exploitation allows arbitrary code execution with SYSTEM privileges.
| Vendor | Product | Versions |
|---|---|---|
Falconstor Software | Disk Pulse Enterprise | affected 9.0.34 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now