CVE-2020-37185: Nsasoft Nsauditor Backup Key Recovery

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash.

Affected products

  • Nsasoft Nsauditor Backup Key Recovery: version 2.2.5 only

Published 2026-02-11. Last modified 2026-06-17.