Cyber Resilience

CVE-2018-25360

HighPublic PoC

Published: 25 May 2026

Published
25 May 2026
Modified
26 May 2026
KEV Added
Patch
CVSS Score v4 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0019 8.7th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2018-25360 is a high-severity Stack-based Buffer Overflow (CWE-121) vulnerability in Agatasoft (inferred from references). Its CVSS base score is 8.6 (High).

Operationally, ranked at the 8.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability details

AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious ping.txt file with shellcode and…

more

jump instructions that overwrite the SEH handler pointer to achieve code execution when the file contents are pasted into the application.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-70083Shared CWE-121
CVE-2026-38422Shared CWE-121
CVE-2025-54485Shared CWE-121
CVE-2025-11783Shared CWE-121
CVE-2025-29149Shared CWE-121
CVE-2025-15273Shared CWE-121
CVE-2025-54491Shared CWE-121
CVE-2025-70656Shared CWE-121
CVE-2025-70304Shared CWE-121
CVE-2025-71023Shared CWE-121

Affected Assets

Agatasoft
inferred from references and description; NVD did not file a CPE for this CVE

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References