Junglewise Threat Intelligence

CVE-2019-25711: Nsasoft SpotFTP Password Recover denial of service in Name field

CVE-2019-25711 · Severity: medium · CVSS 6.2 · Published 2026-04-12

Technologies: Nsasoft Spotftp. Vendors: Nsasoft.

Executive brief

SpotFTP Password Recover, a tool used to retrieve lost FTP credentials, is vulnerable to a flaw that allows a local user to crash the software. By entering an excessively long name during the product registration process, an attacker can cause the application to stop responding. This impact is limited to the local machine and primarily affects the availability of the password recovery tool.

Technical details

A denial of service vulnerability exists in SpotFTP Password Recover 2.4.2 due to improper handling of input length in the registration interface. A local attacker can trigger a crash by inputting a 256-byte payload into the 'Name' field and submitting a registration code. The vulnerability appears to be a buffer overflow or similar memory corruption issue resulting from reliance on untrusted inputs (CWE-807). While the primary reported impact is application instability (DoS), some scoring assessments suggest potential for broader memory access. No official patch is currently documented in the advisory.

Affected products

  • Nsasoft SpotFTP Password Recover 2.4.2

Timeline

  • 2019-01-04: other: Vulnerability discovered
  • 2019-01-07: disclosed: Exploit-DB PoC published
  • 2026-04-12: advisory: NVD/VulnCheck advisory published

References

Related threats