← Vulnerability feed

Vulnerability record · CVE-2006-5780 · published 7 November 2006

CVE-2006-5780: XLink Omni-NFS Server nfsd.exe stack buffer overflow

Xlink Technology · Omni Nfs Server

XLink Omni-NFS Server 5.2 contains a stack-based buffer overflow in nfsd.exe reachable over TCP port 2049. A crafted packet can overwrite stack memory and lead to remote code execution. The flaw is remotely reachable without authentication, making any exposed NFS service instance a direct target.

7.5 CVSS 2.0 High EPSS 62% · top 0.8%
7.5CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet to port 2049 (nfsd), as demonstrated by vd_xlink.pm.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote, unauthenticated code execution with public exploit code and very high EPSS, though not confirmed in KEV.

What it is

XLink Omni-NFS Server 5.2 contains a stack-based buffer overflow in nfsd.exe reachable over TCP port 2049. A crafted packet can overwrite stack memory and lead to remote code execution. The flaw is remotely reachable without authentication, making any exposed NFS service instance a direct target.

Impact

An unauthenticated remote attacker can execute arbitrary code in the context of the nfsd.exe service, potentially gaining full control of the host. The CVSS 2.0 vector shows partial confidentiality, integrity and availability impact.

Attack surface

Reached over the network via a crafted TCP packet to port 2049 (nfsd); the AV:N/AC:L/Au:N vector indicates no authentication and no user interaction are required. Any host exposing this service to untrusted networks is in scope.

Exploitation

Public exploit code is referenced (Exploit-DB 2729, SecurityFocus BID 20941, GLEG VULNDISCO), and EPSS is 0.617 with a 99.1 percentile, indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is recorded here.

What to do

  • Patch or upgrade XLink Omni-NFS Server beyond 5.2, or replace the product if no fixed release exists.
  • Block TCP port 2049 from untrusted networks and restrict NFS access to trusted hosts only.
  • Run nfsd.exe with least privilege and isolate the service on a segmented network.
  • Monitor vendor and exploit-database advisories for updated fixes and workarounds.

Detection

  • Alert on unexpected or malformed TCP traffic to port 2049, especially oversized packets.
  • Monitor nfsd.exe for crashes or abnormal process termination that may indicate exploitation attempts.
  • Watch for child processes or outbound connections spawned by nfsd.exe, which would suggest code execution.
  • Use IDS/IPS signatures for the known exploit (Exploit-DB 2729) against port 2049.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-5780 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2006-5780), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.