Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. Attackers can craft a malicious MobaXterm sessions file with overflow data that triggers the vulnerability when imported and executed, enabling reverse shell execution with user privileges.
History

Thu, 04 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Description Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. Attackers can craft a malicious MobaXterm sessions file with overflow data that triggers the vulnerability when imported and executed, enabling reverse shell execution with user privileges.
Title Mobatek MobaXterm 12.1 Buffer Overflow via Sessions File
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-04T13:22:45.443Z

Reserved: 2026-06-04T11:11:45.519Z

Link: CVE-2019-25741

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T14:16:32.787

Modified: 2026-06-04T14:16:32.787

Link: CVE-2019-25741

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.