CVE-2013-4742: Netwin Surgeftp

High severity, CVSS 7.5. EPSS: 4.3% chance of exploitation in the next 30 days.

Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request.

Affected products

  • Netwin Surgeftp: up to and including 2.3b1; version 2.0c only; version 2.0d only; version 2.0e only; version 2.0f only; version 2.2k1 only; …

Published 2013-08-09. Last modified 2026-06-16.