Junglewise Threat Intelligence

CVE-2020-37208: Nsasoft SpotFTP buffer overflow in registration key field

CVE-2020-37208 · Severity: high · CVSS 7.5 · Published 2026-02-11

Technologies: Nsasoft Spotftp. Vendors: Nsasoft.

Executive brief

SpotFTP, a tool used for recovering FTP passwords, contains a flaw in its registration system. An attacker can cause the application to crash and become unusable by entering an excessively long registration key. This results in a denial of service, preventing legitimate users from accessing the software's features.

Technical details

A buffer overflow vulnerability exists in SpotFTP version 3.0.0.0 within the registration key input field. The flaw is classified as an out-of-bounds write (CWE-787) triggered when the application fails to properly validate the length of the input provided in the 'Key' field. An attacker can exploit this by pasting a payload of approximately 1,000 characters into the registration dialog, leading to memory corruption and an application crash (Denial of Service). While some sources suggest a network vector, the primary exploit method requires local interaction with the application's GUI. A public Proof of Concept (PoC) is available.

Affected products

  • Nsasoft (Nsauditor) SpotFTP FTP Password Recovery 3.0.0.0

Timeline

  • 2020-01-06: disclosed: Initial PoC published on Exploit-DB
  • 2026-02-11: advisory: NVD/VulnCheck advisory published

References

Related threats