CVE-2020-25066: Treck Tcp/ip

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code.

Affected products

  • Treck Tcp/ip: before 6.0.1.68 (fixed in 6.0.1.68)

Published 2020-12-22. Last modified 2026-06-17.