Unquoted Service Path Vulnerability in TFTP Broadband by TFTP
CVE-2020-37250
Key Information:
- Vendor
Weird-solutions
- Status
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2020-37250?
The TFTP Broadband 4.3.0.1465 version suffers from an unquoted service path vulnerability within the tftpt.exe service binary. This flaw enables local attackers to exploit the service by placing a malicious executable in the Program Files directory path, allowing it to be executed with LocalSystem privileges during service startup or system reboot. This vulnerability presents a significant risk as it can lead to arbitrary code execution with high-level system access.
Affected Version(s)
TFTP Broadband 4.3.0.1465
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
