CVE-2020-37250: Weird-Solutions Tftp Broadband
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows local attackers to execute arbitrary code with system privileges. Attackers can place a malicious executable in the Program Files directory path that will be executed during service startup or system reboot with LocalSystem privileges.
Affected products
- Weird-Solutions Tftp Broadband: version 4.3.0.1465 only
Published 2026-06-19. Last modified 2026-09-29.