VYPR
Unrated severityNVD Advisory· Published Feb 11, 2026· Updated Feb 12, 2026

SpotFTP FTP Password Recovery 3.0.0.0 - 'Name' Denial of Service

CVE-2020-37209

Description

SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

Affected products

2
  • Nsasoft/Spotftpllm-fuzzy
    Range: = 3.0.0.0
  • Nsasoft/Nsauditor SpotFTP FTP Password Recoveryv5
    Range: 3.0.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.