Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-25262

21
FAUCET Score

BRIEFING NOTE: CVE-2018-25262 Angry IP Scanner version 3.5.3 for Linux contains a denial of service vulnerability triggered by malformed input in the port selection field. Local attackers can craft a malicious string with buffer overflow patterns and paste it into the Preferences Ports tab to crash the application. The vulnerability has a CVSS score of 6.2 (Medium) with a local attack vector requiring no privileges or user interaction. The attack has low complexity and results in high availability impact, as the application terminates unexpectedly. However, there is no impact to confidentiality or integrity of data. This vulnerability is not listed on the Known Exploited Vulnerabilities catalog and shows minimal community attention with an EPSS score in the lowest percentile (0.000120000), indicating low real-world exploitation probability. No active exploitation or public exploit code has been identified, and the issue remains on the inactive hot list with a FAUCET risk score of 43/100. Organizations running Angry IP Scanner 3.5.3 should update to a patched version, though immediate action is not critical given the low exploitation risk.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.5.3CPE matchmatch criteria
cpe:2.3:a:angryip:angry_ip_scanner:*:*:*:*:*:linux:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 17th percentile among its peer group of 3,048 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

angryip.org
Product
exploit-db.com / exploits/46038
ExploitVDB Entry
vulncheck.com / advisories/angry-ip-scanner-for-linux-denial-of-service
Third Party Advisory