Junglewise Threat Intelligence

CVE-2019-25705: Interference Security Echo Mirage stack buffer overflow in Rules action field

CVE-2019-25705 · Severity: high · CVSS 8.4 · Published 2026-04-12

Executive brief

Echo Mirage is a network proxy tool used by security professionals to monitor and modify traffic from desktop applications. A vulnerability in the software allows a local user to crash the application or potentially take control of the computer by entering an excessively long string of text into the application's rules configuration. This could lead to unauthorized code execution or a complete loss of service for the tool.

Technical details

A stack-based buffer overflow (CWE-787) exists in Echo Mirage version 3.1 and earlier. The vulnerability is triggered when a user provides an oversized string (approximately 24,241 bytes) in the 'action' field within the 'Rules' dialog. By pasting a specially crafted payload into this field, an attacker can overwrite the return address on the stack. This can lead to a denial-of-service (application crash) or arbitrary code execution with the privileges of the user running the application. The attack requires local access to the interface but does not require specific administrative privileges.

Affected products

  • Interference Security Echo Mirage 3.1 and earlier

Timeline

  • 2019-01-21: disclosed: Initial PoC exploit published on Exploit-DB
  • 2026-04-12: advisory: NVD/VulnCheck advisory published

References