← Vulnerability feed

Vulnerability record · CVE-2006-4948 · published 23 September 2006

CVE-2006-4948: ProSysInfo TFTPDWIN tftpd.exe stack buffer overflow via long filename

PProsysinfo · Tftp Server Tftpdwin

ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier contains a stack-based buffer overflow in tftpd.exe triggered by a long file name. A remote, unauthenticated attacker can send a crafted request to corrupt memory, leading to arbitrary code execution or a denial of service. The record notes the provenance of this information is unknown and details come from third-party sources, so the description is thin.

7.5 CVSS 2.0 High EPSS 55% · top 1.0%
7.5CVSS 2.0 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution with a high EPSS score, though the record lacks patch and exploit confirmation.

What it is

ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier contains a stack-based buffer overflow in tftpd.exe triggered by a long file name. A remote, unauthenticated attacker can send a crafted request to corrupt memory, leading to arbitrary code execution or a denial of service. The record notes the provenance of this information is unknown and details come from third-party sources, so the description is thin.

Impact

An attacker gains the ability to execute arbitrary code in the context of the tftpd.exe process, or to crash the service, disrupting TFTP file transfers.

Attack surface

The flaw is reached over the network through the TFTP service on tftpd.exe, with no authentication required per the AV:N/AC:L/Au:N vector. No user interaction is indicated.

Exploitation

Not listed in CISA KEV and no public exploit tag is present in the references, though EPSS is high at 0.5498 (99th percentile), suggesting elevated likelihood of attempted exploitation.

What to do

  • Upgrade TFTPDWIN past 0.4.2 or replace it with a maintained TFTP server, since no patch detail is given in the record.
  • Restrict TFTP access to trusted hosts and networks using firewall or ACL rules, and block UDP port 69 from untrusted sources.
  • Run the TFTP service with least privilege and isolate it from sensitive data and management networks.
  • Disable the TFTP service entirely where it is not required.

Detection

  • Monitor TFTP request logs for abnormally long file names or malformed packets targeting tftpd.exe.
  • Watch for tftpd.exe process crashes or restarts that correlate with inbound TFTP traffic.
  • Alert on unexpected child processes or outbound connections originating from the TFTP server host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-4948 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-4948), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.