Vulnerability record · CVE-2009-2227 · published 26 June 2009
CVE-2009-2227: Bopup Communication Server stack buffer overflow on TCP port 19810
BBlabsoft · Bopup Communication Server
B Labs Bopup Communication Server 3.2.26.5460 contains a stack-based buffer overflow reachable through a crafted request to TCP port 19810. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the server. The record does not state whether a fixed version exists, so affected-version scope beyond the named build is unknown.
Description
Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request to TCP port 19810.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote, unauthenticated code execution with a 10.0 CVSS score and public exploit code, though no confirmed in-the-wild or KEV activity is documented.
What it is
B Labs Bopup Communication Server 3.2.26.5460 contains a stack-based buffer overflow reachable through a crafted request to TCP port 19810. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the server. The record does not state whether a fixed version exists, so affected-version scope beyond the named build is unknown.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the Bopup Communication Server process, which typically runs with service-level privileges. That allows full compromise of the messaging server and any data or downstream clients it manages.
Attack surface
The flaw is reached over the network via TCP port 19810; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host that can reach that port can send the crafted request.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.68581, 99.3rd percentile) and a public Exploit-DB entry (9002) exists, indicating exploit code is publicly available. No ransomware association is documented.
What to do
- Apply the vendor fix for Bopup Communication Server if one is available; the record does not name a patched version, so confirm with B Labs/BLabSoft directly.
- If no patch exists, restrict TCP port 19810 to trusted management hosts using host or network firewalls.
- Place the server behind a reverse proxy or filtering device that can reject malformed or oversized requests to port 19810.
- Run the service under a least-privilege account and isolate the host from other critical systems.
- Monitor vendor advisories (Secunia/VUPEN references) for an updated build and upgrade as soon as one is published.
Detection
- Monitor network traffic to TCP port 19810 for oversized or malformed request payloads and alert on anomalies.
- Watch for crashes or restarts of the Bopup Communication Server process, which can indicate a failed overflow attempt.
- Inspect host logs for unexpected child processes or command execution spawned by the Bopup service account.
- Use IDS/IPS signatures for the public Exploit-DB 9002 exploit pattern against port 19810.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-2227 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-2227), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.