---
id: CVE-2018-25228
title: >-
  NetSetMan 4.7.1 contains a buffer overflow vulnerability in the Workgroup
  feature that allows local attackers to crash the application by supplying
  oversized input
summary: >-
  NetSetMan 4.7.1 contains a buffer overflow vulnerability in the Workgroup
  feature that allows local attackers to crash the application by supplying
  oversized input. Attackers can create a malicious configuration file with
  excessive data …
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-787
vendor: netsetman
product: netsetman
affected:
  - netsetman = 4.7.1
published: '2026-03-30'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T08:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25228'
references:
  - url: 'https://www.exploit-db.com/exploits/46417'
    label: disclosure@vulncheck.com
  - url: 'https://www.netsetman.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.netsetman.com/netsetman.exe'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/netsetman-workgroup-buffer-overflow-denial-of-service
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00221
epssPercentile: 0.11546
ingestedAt: '2026-10-07T08:20:03.909Z'
---

## Overview

NetSetMan 4.7.1 contains a buffer overflow vulnerability in the Workgroup feature that allows local attackers to crash the application by supplying oversized input. Attackers can create a malicious configuration file with excessive data and paste it into the Workgroup field to trigger a denial of service condition.

## Affected

- `netsetman = 4.7.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
