CVE Database
/

CVE-2025-34108

Back to search

CVE-2025-34108

Published: Jul 15, 2025

Modified: Apr 7, 2026

PUBLISHED

Description

A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. An attacker can send a specially crafted HTTP POST request to the /login endpoint with an overly long username parameter, causing a buffer overflow in the libspp.dll component. Successful exploitation allows arbitrary code execution with SYSTEM privileges.

VendorProductVersions

Falconstor Software

Disk Pulse Enterprise

affected
9.0.34

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now