Vulnerability record · CVE-2019-25626 · published 24 March 2026
CVE-2019-25626: River past cam do project river past cam do unrestricted file upload vulnerability
RRiver Past Cam Do Project · River Past Cam Do
River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows local attackers to execute arbitrary code by supplying a malicious activation code string. Attackers can craft a buffer containing 608 bytes of junk data followed by shellcode and SEH chain overwrite values to trigger code execution when the activation dialog processes the input.
Description
River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows local attackers to execute arbitrary code by supplying a malicious activation code string. Attackers can craft a buffer containing 608 bytes of junk data followed by shellcode and SEH chain overwrite values to trigger code execution when the activation dialog processes the input.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.flexhex.com | Not Applicable |
| https://en.softonic.com/download/river-past-cam-do/windows/post-download?sl=1 | Product |
| https://www.exploit-db.com/exploits/46670 | ExploitVDB Entry |
| https://www.vulncheck.com/advisories/river-past-cam-do-local-buffer-overflow-in-activation-code | Third Party Advisory |
Track CVE-2019-25626 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-25626), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.