CVE-2019-25546: Spytech-Web Netaware

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

NetAware 1.20 contains a buffer overflow vulnerability in the Share Name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by pasting a 1000-byte buffer into the Share Name parameter when adding a new share through the Manage Shares interface.

Affected products

Published 2026-03-21. Last modified 2026-06-17.