TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows local attackers to execute arbitrary code with system privileges. Attackers can place a malicious executable in the Program Files directory path that will be executed during service startup or system reboot with LocalSystem privileges.
References
Configurations
No configuration.
History
19 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-19 15:16
Updated : 2026-06-22 21:14
NVD link : CVE-2020-37250
Mitre link : CVE-2020-37250
CVE.ORG link : CVE-2020-37250
JSON object : View
Products Affected
No product.
CWE
CWE-428
Unquoted Search Path or Element
