CVE-2020-36881

Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Input Directory' component that allows unauthenticated attackers to execute arbitrary code on the system. Attackers can exploit this by pasting a specially crafted directory path into the 'Add Input Directory' field.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flexense:diskboss:7.7.14:*:*:*:*:*:*:*

History

10 Dec 2025, 15:10

Type Values Removed Values Added
References () https://github.com/x00x00x00x00/diskboss_7.7.14/raw/master/ - () https://github.com/x00x00x00x00/diskboss_7.7.14/raw/master/ - Broken Link
References () https://github.com/x00x00x00x00/diskboss_7.7.14/raw/master/diskboss_setup_v7.7.14.exe - () https://github.com/x00x00x00x00/diskboss_7.7.14/raw/master/diskboss_setup_v7.7.14.exe - Product
References () https://www.diskboss.com/ - () https://www.diskboss.com/ - Product
References () https://www.exploit-db.com/exploits/48279 - () https://www.exploit-db.com/exploits/48279 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/flexsense-diskboss-add-input-directory-buffer-overflow - () https://www.vulncheck.com/advisories/flexsense-diskboss-add-input-directory-buffer-overflow - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Flexense diskboss
Flexense
CPE cpe:2.3:a:flexense:diskboss:7.7.14:*:*:*:*:*:*:*

05 Dec 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-05 18:15

Updated : 2025-12-10 15:10


NVD link : CVE-2020-36881

Mitre link : CVE-2020-36881

CVE.ORG link : CVE-2020-36881


JSON object : View

Products Affected

flexense

  • diskboss
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer