Vulnerability record · CVE-2006-5780 · published 7 November 2006
CVE-2006-5780: XLink Omni-NFS Server nfsd.exe stack buffer overflow
Xlink Technology · Omni Nfs Server
XLink Omni-NFS Server 5.2 contains a stack-based buffer overflow in nfsd.exe reachable over TCP port 2049. A crafted packet can overwrite stack memory and lead to remote code execution. The flaw is remotely reachable without authentication, making any exposed NFS service instance a direct target.
Description
Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet to port 2049 (nfsd), as demonstrated by vd_xlink.pm.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with public exploit code and very high EPSS, though not confirmed in KEV.
What it is
XLink Omni-NFS Server 5.2 contains a stack-based buffer overflow in nfsd.exe reachable over TCP port 2049. A crafted packet can overwrite stack memory and lead to remote code execution. The flaw is remotely reachable without authentication, making any exposed NFS service instance a direct target.
Impact
An unauthenticated remote attacker can execute arbitrary code in the context of the nfsd.exe service, potentially gaining full control of the host. The CVSS 2.0 vector shows partial confidentiality, integrity and availability impact.
Attack surface
Reached over the network via a crafted TCP packet to port 2049 (nfsd); the AV:N/AC:L/Au:N vector indicates no authentication and no user interaction are required. Any host exposing this service to untrusted networks is in scope.
Exploitation
Public exploit code is referenced (Exploit-DB 2729, SecurityFocus BID 20941, GLEG VULNDISCO), and EPSS is 0.617 with a 99.1 percentile, indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is recorded here.
What to do
- Patch or upgrade XLink Omni-NFS Server beyond 5.2, or replace the product if no fixed release exists.
- Block TCP port 2049 from untrusted networks and restrict NFS access to trusted hosts only.
- Run nfsd.exe with least privilege and isolate the service on a segmented network.
- Monitor vendor and exploit-database advisories for updated fixes and workarounds.
Detection
- Alert on unexpected or malformed TCP traffic to port 2049, especially oversized packets.
- Monitor nfsd.exe for crashes or abnormal process termination that may indicate exploitation attempts.
- Watch for child processes or outbound connections spawned by nfsd.exe, which would suggest code execution.
- Use IDS/IPS signatures for the known exploit (Exploit-DB 2729) against port 2049.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5780 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2006-5780), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.