CRITICAL🇵🇱 Wersja polska

CVE-2018-25221

CVSS 9.3v4.0pub. 2026-03-28upd. 2026-04-02

EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code execution in the application context.

🤖 AI Analysis
How it works

An attacker sends a GET request to the chat.ghp endpoint, passing an excessively long value in the username parameter. The buffer overflow (CWE-787: out-of-bounds write) allows overwriting the application's memory. In the crafted payload, the attacker places shellcode and ROP (Return-Oriented Programming) gadgets, which enables hijacking the execution flow and executing arbitrary code in the context of the server process.

Impact

An attacker can remotely execute arbitrary code (RCE) in the context of the EChat Server application without any authentication, which can lead to full compromise of the server.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references. Due to the publicly available exploit (Exploit-DB 44155), it is recommended to prioritize decommissioning or network isolation of vulnerable instances until the patch is deployed.

Who is affected

EChat Server (Easy Chat Server) version 3.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Echatserver Easy Chat Server

    APP
    Echatserver
    ≤ 3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2017-9544CRITICAL9.8PL ✓same product

RCE via stack-based buffer overflow w Easy Chat Server (SEH)

CVE-2019-25613HIGH8.7same product

Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the appl...

CVE-2022-44939HIGH7.8same product

Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the comp...

CVE-2019-20502HIGH7.5same product

An issue was discovered in EFS Easy Chat Server 3.1. There is a buffer overflow via a long body2.ghp message p...

CVE-2017-9543HIGH7.5same product

register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary p...