Vulnerability record · CVE-2005-1812 · published 1 June 2005
CVE-2005-1812: FutureSoft TFTP Server stack buffer overflow via RRQ/WRQ strings
FFuturesoft · Tftp Server 2000
FutureSoft TFTP Server Evaluation Version 1.0.0.1 contains multiple stack-based buffer overflows in its handling of Read Request (RRQ) and Write Request (WRQ) packets. A long filename or transfer mode string overflows a stack buffer, allowing remote code execution. The flaw is remotely reachable over the network with no authentication, making it a serious exposure for any host running this TFTP service.
Description
Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityUnauthenticated remote code execution with complete impact and public exploit references, though the product is an old evaluation build and no KEV listing exists.
What it is
FutureSoft TFTP Server Evaluation Version 1.0.0.1 contains multiple stack-based buffer overflows in its handling of Read Request (RRQ) and Write Request (WRQ) packets. A long filename or transfer mode string overflows a stack buffer, allowing remote code execution. The flaw is remotely reachable over the network with no authentication, making it a serious exposure for any host running this TFTP service.
Impact
An unauthenticated remote attacker can execute arbitrary code with the privileges of the TFTP service, typically leading to full host compromise. Given the CVSS 2.0 vector of complete confidentiality, integrity and availability impact, the attacker gains control of the affected system.
Attack surface
The service is reached over the network via TFTP UDP packets; the CVSS vector AV:N/Au:N confirms no authentication is required. No user interaction is described, and the vulnerable input is the filename or transfer mode field of an RRQ or WRQ packet.
Exploitation
CVE-2005-1812 is not listed in CISA KEV, but public exploit references exist (SecurityFocus BID 13821 and security.org.sg advisory tagged Exploit). EPSS gives a 30-day probability of 0.62916 (99.16th percentile), indicating high predicted exploitation activity.
What to do
- Upgrade or replace FutureSoft TFTP Server Evaluation Version 1.0.0.1; the record does not name a fixed version, so confirm with the vendor or migrate to a maintained TFTP implementation.
- If the service cannot be patched, restrict TFTP access to trusted management networks and block UDP port 69 from untrusted sources.
- Disable the TFTP service entirely on hosts that do not require it.
- Run the TFTP service under a low-privilege account and isolate it from sensitive data and management interfaces.
- Monitor vendor and CVE feeds for a fixed release, since no patch version is stated in this record.
Detection
- Inspect TFTP RRQ/WRQ packet captures for abnormally long filename or transfer mode strings that exceed expected field lengths.
- Alert on TFTP service crashes or restarts, which may indicate a failed or successful overflow attempt.
- Monitor for unexpected child processes or outbound connections spawned by the TFTP service process.
- Review network logs for TFTP traffic from untrusted or external source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-1812 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-1812), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.