CVE-2025-34105: Flexense Diskboss Enterprise

Critical severity, CVSS 10.0. EPSS: 1.6% chance of exploitation in the next 30 days.

A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vulnerability arises from improper bounds checking on the path component of HTTP GET requests. By sending a specially crafted long URI, a remote unauthenticated attacker can trigger a buffer overflow, potentially leading to arbitrary code execution with SYSTEM privileges on vulnerable Windows hosts.

Affected products

  • Flexense Diskboss Enterprise: version 7.4.28 only; version 7.5.12 only; version 8.2.14 only

Published 2025-07-15. Last modified 2026-06-17.