CVE-2020-1939: Apache Nuttx
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs. One of these, ftpd, had a NULL pointer dereference bug. The NuttX RTOS itself is not affected. Users of the optional apps repository are affected only if they have enabled ftpd. Versions 6.15 to 8.2 are affected.
Affected products
- Apache Nuttx: from 6.15, up to and including 8.2
Published 2020-05-12. Last modified 2026-06-17.