Skip to main content

CVE-2025-34108

CVSS Score Not Available
70.48%
HIGH RiskEPSS (99th percentile)

A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. An attacker can send a specially crafted HTTP POST request to the /login endpoint with an overly long username parameter, causing a buffer overflow in the libspp.dll component. Successful exploitation allows arbitrary code execution with SYSTEM privileges.

Published: 7/15/2025
Modified: 4/15/2026
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

70.48%HIGH Exploitation Risk
99th percentile

This vulnerability has a 70.48% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-121, CWE-20)