CVE-2025-34105: Flexense Diskboss Enterprise
Critical severity, CVSS 10.0. EPSS: 1.6% chance of exploitation in the next 30 days.
A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vulnerability arises from improper bounds checking on the path component of HTTP GET requests. By sending a specially crafted long URI, a remote unauthenticated attacker can trigger a buffer overflow, potentially leading to arbitrary code execution with SYSTEM privileges on vulnerable Windows hosts.
Affected products
- Flexense Diskboss Enterprise: version 7.4.28 only; version 7.5.12 only; version 8.2.14 only
Published 2025-07-15. Last modified 2026-06-17.