Vulnerability record · CVE-2006-6183 · published 1 December 2006
CVE-2006-6183: 3Com 3CTftpSvc TFTP mode field stack buffer overflow
3com · 3ctftpsvc
3Com 3CTftpSvc 2.0.1 (and possibly earlier) contains multiple stack-based buffer overflows triggered by an overlong mode field in TFTP GET or PUT commands. A remote, unauthenticated attacker can crash the service or potentially execute arbitrary code on the host. The flaw is remotely reachable over the network with no credentials required.
Description
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long mode field (aka transporting mode) in a (1) GET or (2) PUT command.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityRemote, unauthenticated, low-complexity buffer overflow with a CVSS 2.0 score of 10, public exploit references, and a very high EPSS probability.
What it is
3Com 3CTftpSvc 2.0.1 (and possibly earlier) contains multiple stack-based buffer overflows triggered by an overlong mode field in TFTP GET or PUT commands. A remote, unauthenticated attacker can crash the service or potentially execute arbitrary code on the host. The flaw is remotely reachable over the network with no credentials required.
Impact
An attacker can cause a denial of service by crashing the TFTP service, or potentially execute arbitrary code with the privileges of the service process. Successful code execution would give the attacker a foothold on the affected host.
Attack surface
Reached over the network via the TFTP service, which is inherently unauthenticated; no user interaction is required. The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C confirms remote, low-complexity, unauthenticated exploitation.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.70293, 99.35th percentile) and two SecurityFocus references are tagged Exploit, indicating public exploit material exists. No ransomware group usage is documented.
What to do
- Apply the vendor patch or upgrade 3CTftpSvc to a fixed version if one is available; if no fix exists, retire or replace the product.
- Restrict TFTP access to trusted management networks and block UDP port 69 from untrusted sources at the perimeter.
- Disable the TFTP service entirely on hosts that do not require it.
- Segment or isolate hosts running 3CTftpSvc to limit lateral movement if code execution succeeds.
- Monitor vendor advisories for updated guidance since the record is old and may lack current patch information.
Detection
- Inspect TFTP traffic for GET/PUT requests with abnormally long mode fields or oversized packets.
- Alert on crashes or unexpected restarts of the 3CTftpSvc process.
- Monitor for unexpected outbound connections or new processes spawned by the TFTP service, which may indicate code execution.
- Review network logs for TFTP requests originating from untrusted or unexpected source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-6183 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-6183), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.