Vulnerability record · CVE-2006-4948 · published 23 September 2006
CVE-2006-4948: ProSysInfo TFTPDWIN tftpd.exe stack buffer overflow via long filename
PProsysinfo · Tftp Server Tftpdwin
ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier contains a stack-based buffer overflow in tftpd.exe triggered by a long file name. A remote, unauthenticated attacker can send a crafted request to corrupt memory, leading to arbitrary code execution or a denial of service. The record notes the provenance of this information is unknown and details come from third-party sources, so the description is thin.
Description
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with a high EPSS score, though the record lacks patch and exploit confirmation.
What it is
ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier contains a stack-based buffer overflow in tftpd.exe triggered by a long file name. A remote, unauthenticated attacker can send a crafted request to corrupt memory, leading to arbitrary code execution or a denial of service. The record notes the provenance of this information is unknown and details come from third-party sources, so the description is thin.
Impact
An attacker gains the ability to execute arbitrary code in the context of the tftpd.exe process, or to crash the service, disrupting TFTP file transfers.
Attack surface
The flaw is reached over the network through the TFTP service on tftpd.exe, with no authentication required per the AV:N/AC:L/Au:N vector. No user interaction is indicated.
Exploitation
Not listed in CISA KEV and no public exploit tag is present in the references, though EPSS is high at 0.5498 (99th percentile), suggesting elevated likelihood of attempted exploitation.
What to do
- Upgrade TFTPDWIN past 0.4.2 or replace it with a maintained TFTP server, since no patch detail is given in the record.
- Restrict TFTP access to trusted hosts and networks using firewall or ACL rules, and block UDP port 69 from untrusted sources.
- Run the TFTP service with least privilege and isolate it from sensitive data and management networks.
- Disable the TFTP service entirely where it is not required.
Detection
- Monitor TFTP request logs for abnormally long file names or malformed packets targeting tftpd.exe.
- Watch for tftpd.exe process crashes or restarts that correlate with inbound TFTP traffic.
- Alert on unexpected child processes or outbound connections originating from the TFTP server host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-4948 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-4948), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.