Junglewise Threat Intelligence

CVE-2020-37199: Nsasoft NBMonitor buffer overflow in registration key input

CVE-2020-37199 · Severity: high · CVSS 7.5 · Published 2026-02-11

Vendors: Nsasoft.

Executive brief

NBMonitor, a network bandwidth monitoring tool, contains a flaw that allows the application to be crashed by entering an excessively long registration key. An attacker or user can trigger this by pasting a 1,000-character string into the license activation field. This results in a denial-of-service condition where the software becomes unresponsive or closes unexpectedly, potentially disrupting network monitoring activities.

Technical details

A classic buffer overflow (CWE-120) exists in NBMonitor version 1.6.6.0 and potentially earlier versions within the registration key input field. The application fails to perform adequate bounds checking on the 'Key' field during the registration process. An attacker can trigger an application crash (Denial of Service) by supplying a payload of approximately 1,000 characters. While the attack requires local interaction to paste the string into the GUI, some CVSS mappings suggest a network vector if the registration process communicates externally; however, the primary exploit method is local user interaction. A public Proof of Concept (PoC) is available.

Affected products

  • Nsasoft (Nsauditor) NBMonitor 1.6.6.0 and earlier

Timeline

  • 2020-01-06: disclosed: Initial exploit PoC published on Exploit-DB
  • 2026-02-11: advisory: CVE published/updated via VulnCheck and NVD

References

Related threats