CVE-2020-37029: K.soft Ftpdummy

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

FTPDummy 4.80 contains a local buffer overflow vulnerability in its preference file handling that allows attackers to execute arbitrary code. Attackers can craft a malicious preference file with carefully constructed shellcode to trigger a structured exception handler overwrite and execute system commands.

Affected products

  • K.soft Ftpdummy: version 4.80 only

Published 2026-01-30. Last modified 2026-06-17.