CVE-2018-25223Disclosure(ftnapps / crashmail_ii)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for ftnapps crashmail_ii systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crashmail_ii

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-28); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
crashmail_ii

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-28: 3Mentions · 2026-03-29: 2PoC Mentioned / Linked · 2026-03-28: 1Exploit Tool / Code · 2026-03-28: 1Technical Details · 2026-03-28: 303-2803-29
Signal classification3 categories
Disclosure
360.0%
Exploit
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-283
Disclosure2Exploit1
2026-03-292
Disclosure1General1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2018-25223 Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the applicatio… https://www.cve.org/CVERecord?id=CVE-2018-25223

    Post summary

    The item announces that CVE‑2018‑25223 is a stack‑based buffer overflow in Crashmail 1.6 that can lead to remote code execution, without mentioning PoC, exploit code, active use, or a patch.

    0001042
    56.9K followersView on X
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2018-25220 | CVSS 9.8 🔴 CVE-2017-20229 | CVSS 9.8 🔴 CVE-2018-25223 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post simply enumerates three high‑CVSS score CVEs without providing PoC, exploit, patch, or technical details, serving as a straightforward disclosure.

    0000028
    5.6K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2018-25223 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2018-25223 #CVE-2018-25223 #CVE #Critical #CyberSecurity #InfoSec https://t.co/W5TlkfLonw

    Post summary

    The tweet announces the existence of CVE‑2018‑25223 with a high severity score but includes no technical details, exploitation proof, or remediation advice, making its content largely informational.

    0000023
    123 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2018-25223: CRITICAL] Vulnerability alert: Crashmail 1.6 has a stack-based buffer overflow flaw, enabling remote code execution. Attackers can exploit this issue via crafted payloads for malicious impact.#cve,CVE-2018-25223,#cybersecurity https://cvefind.com/CVE-2018-25223

    Post summary

    The post announces a critical stack‑based buffer overflow in Crashmail 1.6 that permits remote code execution, but it offers no PoC, exploit code, or patch information.

    0000020
    617 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2018-25223: Cr... Stack-based RCE with ROP chains ready to go - 9.3 CVSS and exploit-db proof means your legacy mail systems are toast. #RCE #StackOverflow #LegacyPwn. https://zerodaysignal.com/vulnerability/CVE-2018-25223 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a stack‑based RCE in CVE‑2018‑25223, noting an exploit‑DB proof and providing a link for details, but offers no patch, active‑exploitation claims, or false‑positive commentary.

    0000092
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appftnappscrashmail_ii---

Explore more