CVE-2019-25689: Socusoft HTML5 Video Player

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.

Affected products

  • Socusoft HTML5 Video Player: version 1.2.5 only

Published 2026-04-12. Last modified 2026-06-17.