CVE-2019-25741 CRITICAL

CVE-2019-25741: Mobatek MobaXterm 12.1 Buffer Overflow via Sessions File

Vendor Mobatek
Product Mobatek MobaXterm
Weakness CWE-120
Published June 4, 2026
Last update June 4, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. Attackers can craft a malicious MobaXterm sessions file with overflow data that triggers the vulnerability when imported and executed, enabling reverse shell execution with user privileges.

Key dates

02Disclosure timeline

June 4, 2026 CVE published
June 4, 2026 Record updated