PatchSiren cyber security CVE debrief
CVE-2019-25736 Labf CVE debrief
CVE-2019-25736 is a HIGH severity vulnerability in LabF nfsAxe 3.7 Ping Client. The vulnerability allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address to execute calc.exe or other arbitrary commands. The vulnerability has a CVSS score of 8.6.
- Vendor
- Labf
- Product
- LabF nfsAxe
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-04
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-06-04
- Advisory updated
- 2026-07-22
Who should care
Users of LabF nfsAxe 3.7 Ping Client should apply patches or mitigations to prevent local attackers from executing arbitrary code.
Technical summary
The vulnerability is caused by a buffer overflow in the Ping Client of LabF nfsAxe 3.7. The buffer overflow allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field.
Defensive priority
HIGH
Recommended defensive actions
- Apply patches or updates provided by the vendor to fix the buffer overflow vulnerability.
- Use secure coding practices to prevent similar vulnerabilities in the future.
- Limit access to the Ping Client to only trusted users and networks.
Evidence notes
The CVE record was obtained from the official CVE website [cve-org]. The vulnerability details were obtained from the NVD database [nvd]. Additional information was obtained from [ref-4], [ref-5], and [ref-6].
Sources and references
Verified primary and authoritative sources
-
CVE-2019-25736 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-25736
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-25736 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-25736
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/46737
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/labf-nfsaxe-ping-client-buffer-overflow
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.