CVE-2017-17968 is a critical buffer overflow vulnerability in NetTransport Download Manager versions 2.96L and earlier, specifically within the NetTransport.exe component. This flaw allows remote HTTP servers to execute arbitrary code on affected NAS devices by sending a specially crafted, long HTTP response. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. While not currently on CISA's KEV catalog, public exploit modules exist in Metasploit and ExploitDB, indicating readily available tools for exploitation, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.96lCPE matchmatch criteria | cpe:2.3:a:xi-soft:nettransport_download_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.