CVE-2020-37155: Core FTP Lite

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without requiring additional interaction.

Affected products

  • Core FTP Core FTP Lite: version 1.3c Build 1437 only

Published 2026-02-07. Last modified 2026-06-17.