Surgeftp

Vendor:

First CVE: Jul 20, 2001 · Active for 25 years

14
Total CVEs
More Total CVEs than 92% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Surgeftp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2001
25 years ago
Most Recent CVE
Aug 5, 2025
357 days ago

CVE Severity & Scoring

Surgeftp14 CVEs
All CVEs353,173 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (14.3%)
Unknown12 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (14.3%)
High0 (0.0%)
Unknown12 (85.7%)
User Interaction
None1 (7.1%)
Unknown12 (85.7%)
Required1 (7.1%)
Privileges Required
Low0 (0.0%)
High1 (7.1%)
None1 (7.1%)
Unknown12 (85.7%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via cra
Aug 5, 20258.643NOYES
The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length
Feb 27, 20086.431NOYES
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.
Sep 20, 20015.030NOYES
Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitra
Jul 20, 200110.027NONO
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password
Aug 4, 200110.026NONO
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to dec
Jul 20, 20014.626NOYES
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.
Dec 29, 20176.122NONO
The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.
Jul 15, 20078.521NONO
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authenti
Aug 9, 20137.520NONO
Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HT
Jul 15, 20075.816NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
21.4% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Surgeftp

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
23f216.10.9%00
2.3a917.54.3%00
2.3a817.54.3%00
2.3a717.54.3%00
2.3a625.92.7%00
2.3a227.05.5%01
2.3a1217.54.3%00
2.3a1017.54.3%00
2.3a117.54.3%00
2.2m126.33.0%00
2.2k326.33.0%00
2.2k117.54.3%00
2.0f28.84.0%00
2.0e28.84.0%00
2.0d28.84.0%00
2.0c28.84.0%00
2.0b38.22.7%01
2.0a56.92.6%01
1.0b46.22.3%01