Enterprisedt develops the CompleteFTP server, a file-transfer product positioned for managed enterprise use. Its observed vulnerability landscape centers on input-handling and access-control weaknesses including path traversal, command injection, sensitive information disclosure in logs, and use of weak cryptographic algorithms, reflecting the security demands of a network-accessible file server exposed to untrusted input and credential management flows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enterprisedt over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2560CRITICAL This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server. Authentication is not required to exploit | Mar 29, 2023 | 9.1 | 72 | NO | NO |
CVE-2019-16864HIGH CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec comma | Feb 14, 2022 | 8.8 | 31 | NO | NO |
CVE-2019-16116MEDIUM EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator passwor | Oct 2, 2019 | 4.3 | 28 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enterprisedt.
Media articles that mention a CVE ID that affects a product developed by Enterprisedt — matched by CVE ID, not by vendor name.