Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21434 | A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vulnerability arises from improper bounds checking on the path component of HTTP GET requests. By sending a specially crafted long URI, a remote unauthenticated attacker can trigger a buffer overflow, potentially leading to arbitrary code execution with SYSTEM privileges on vulnerable Windows hosts. |
Fri, 21 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flexense
Flexense diskboss |
|
| CPEs | cpe:2.3:a:flexense:diskboss:7.4.28:*:*:*:*:*:*:* cpe:2.3:a:flexense:diskboss:7.5.12:*:*:*:*:*:*:* cpe:2.3:a:flexense:diskboss:8.2.14:*:*:*:*:*:*:* |
|
| Vendors & Products |
Flexense
Flexense diskboss |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Tue, 15 Jul 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 15 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Jul 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 15 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vulnerability arises from improper bounds checking on the path component of HTTP GET requests. By sending a specially crafted long URI, a remote unauthenticated attacker can trigger a buffer overflow, potentially leading to arbitrary code execution with SYSTEM privileges on vulnerable Windows hosts. | |
| Title | DiskBoss Enterprise Stack-Based Buffer Overflow RCE | |
| Weaknesses | CWE-20 CWE-787 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:09:33.315Z
Reserved: 2025-04-15T19:15:22.557Z
Link: CVE-2025-34105
Updated: 2025-07-15T13:39:01.253Z
Status : Deferred
Published: 2025-07-15T13:15:30.107
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-34105
No data.
OpenCVE Enrichment
Updated: 2026-05-11T17:30:15Z
EUVD