CVE-2018-25235 - CVE House
Back to Database
Status published Medium CVE-2018-25235

NetworkActiv Web Server 4.0 Username Field Buffer Overflow DoS

Vulnerability Description

NetworkActiv Web Server 4.0 contains a buffer overflow vulnerability in the username field of the Security options that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by entering a crafted username value exceeding the expected buffer size through the Set username interface.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25235

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Victor Mondragón

Affected Vendor

Networkactiv

View all reports →

Affected Software

NetworkActiv Web Server
Vulnerable Versions:
4.0 Pre-Alpha-3.7.2

Timeline

Official Publish: March 30th, 2026
Last Modified: March 30th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)