Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 05 Jun 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mobatek
Mobatek mobaxterm |
|
| Vendors & Products |
Mobatek
Mobatek mobaxterm |
Thu, 04 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. Attackers can craft a malicious MobaXterm sessions file with overflow data that triggers the vulnerability when imported and executed, enabling reverse shell execution with user privileges. | |
| Title | Mobatek MobaXterm 12.1 Buffer Overflow via Sessions File | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-04T15:06:20.007Z
Reserved: 2026-06-04T11:11:45.519Z
Link: CVE-2019-25741
Updated: 2026-06-04T14:51:43.002Z
Status : Deferred
Published: 2026-06-04T14:16:32.787
Modified: 2026-06-04T15:00:40.757
Link: CVE-2019-25741
No data.
OpenCVE Enrichment
Updated: 2026-06-05T07:45:35Z