← Vulnerability feed

Vulnerability record · CVE-2008-1118 · published 14 March 2008

CVE-2008-1118: Netopia timbuktu pro improper input validation vulnerability

Netopia · Timbuktu Pro

Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.

7.5 CVSS 2.0 High EPSS 2.9% · top 13.4% CWE-20 · Improper input validation
7.5CVSS 2.0 base score
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1118 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-1117Timbuktu Pro Notes directory traversal allows arbitrary file uploadThe Notes (instant message) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows (and possibly 8.7 for Mac OS X) fails to properly sanitize destin…EPSS 69%analysed5.0CVE-2008-1337Netopia timbuktu pro improper input validation vulnerabilityThe instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon cra…EPSS 1.7%5.0CVE-2002-0135Netopia timbuktu pro vulnerabilityNetopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (…EPSS 3.2%5.0CVE-2000-0142Netopia timbuktu pro vulnerabilityThe authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.EPSS 8.0%5.0CVE-2000-0086Netopia timbuktu pro vulnerabilityNetopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.EPSS 1.4%9.5CVE-2026-88771Citrix netscaler application delivery controller improper input validation vulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 1.1%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2008-1118), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.