Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 17 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nsasoft
Nsasoft spotftp |
|
| CPEs | cpe:2.3:a:nsasoft:spotftp:2.4.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Nsasoft
Nsasoft spotftp |
Mon, 13 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nsauditor
Nsauditor spotftp Password Recover |
|
| Vendors & Products |
Nsauditor
Nsauditor spotftp Password Recover |
Sun, 12 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash when submitting the registration code. | |
| Title | SpotFTP Password Recover 2.4.2 Denial of Service via Name Field | |
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-13T15:13:03.838Z
Reserved: 2026-04-12T12:19:23.786Z
Link: CVE-2019-25711
Updated: 2026-04-13T15:12:35.929Z
Status : Analyzed
Published: 2026-04-12T13:16:34.300
Modified: 2026-04-17T14:14:50.820
Link: CVE-2019-25711
No data.
OpenCVE Enrichment
Updated: 2026-04-13T12:54:08Z