CVE-2019-25736: Labf Nfsaxe

High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.

LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address to execute calc.exe or other arbitrary commands.

Affected products

  • Labf Labf Nfsaxe: version 3.7 only

Published 2026-06-04. Last modified 2026-07-22.