CVE-2012-10035: Turbosoft, Inc Turboftp Server

Critical severity, CVSS 10.0. EPSS: 1.5% chance of exploitation in the next 30 days.

Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT command. By sending a specially crafted payload, an unauthenticated remote attacker can overwrite memory structures and execute arbitrary code with SYSTEM privileges.

Affected products

  • Turbosoft, Inc Turboftp Server: version 1.30.823 only; version 1.30.826 only

Published 2025-08-05. Last modified 2026-06-16.