Surgeftp
Vendor:
First CVE: Jul 20, 2001 · Active for 25 years
14
Total CVEs
More Total CVEs than 92% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Surgeftp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2001
25 years ago
Most Recent CVE
Aug 5, 2025
357 days ago
CVE Severity & Scoring
Surgeftp14 CVEs
64%
36%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (14.3%)
Unknown12 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (14.3%)
High0 (0.0%)
Unknown12 (85.7%)
User Interaction
None1 (7.1%)
Unknown12 (85.7%)
Required1 (7.1%)
Privileges Required
Low0 (0.0%)
High1 (7.1%)
None1 (7.1%)
Unknown12 (85.7%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-10028HIGH Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via cra | Aug 5, 2025 | 8.6 | 43 | NO | YES |
CVE-2008-1052MEDIUM The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length | Feb 27, 2008 | 6.4 | 31 | NO | YES |
CVE-2001-0697MEDIUM NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command. | Sep 20, 2001 | 5.0 | 30 | NO | YES |
CVE-2001-1355HIGH Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitra | Jul 20, 2001 | 10.0 | 27 | NO | NO |
CVE-2001-1356HIGH NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password | Aug 4, 2001 | 10.0 | 26 | NO | NO |
CVE-2001-1354MEDIUM NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to dec | Jul 20, 2001 | 4.6 | 26 | NO | YES |
CVE-2017-17933MEDIUM cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter. | Dec 29, 2017 | 6.1 | 22 | NO | NO |
CVE-2007-3768HIGH The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command. | Jul 15, 2007 | 8.5 | 21 | NO | NO |
CVE-2013-4742HIGH Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authenti | Aug 9, 2013 | 7.5 | 20 | NO | NO |
CVE-2007-3769MEDIUM Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HT | Jul 15, 2007 | 5.8 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
21.4% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Surgeftp
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 23f2 | 1 | 6.1 | 0.9% | 0 | 0 |
| 2.3a9 | 1 | 7.5 | 4.3% | 0 | 0 |
| 2.3a8 | 1 | 7.5 | 4.3% | 0 | 0 |
| 2.3a7 | 1 | 7.5 | 4.3% | 0 | 0 |
| 2.3a6 | 2 | 5.9 | 2.7% | 0 | 0 |
| 2.3a2 | 2 | 7.0 | 5.5% | 0 | 1 |
| 2.3a12 | 1 | 7.5 | 4.3% | 0 | 0 |
| 2.3a10 | 1 | 7.5 | 4.3% | 0 | 0 |
| 2.3a1 | 1 | 7.5 | 4.3% | 0 | 0 |
| 2.2m1 | 2 | 6.3 | 3.0% | 0 | 0 |
| 2.2k3 | 2 | 6.3 | 3.0% | 0 | 0 |
| 2.2k1 | 1 | 7.5 | 4.3% | 0 | 0 |
| 2.0f | 2 | 8.8 | 4.0% | 0 | 0 |
| 2.0e | 2 | 8.8 | 4.0% | 0 | 0 |
| 2.0d | 2 | 8.8 | 4.0% | 0 | 0 |
| 2.0c | 2 | 8.8 | 4.0% | 0 | 0 |
| 2.0b | 3 | 8.2 | 2.7% | 0 | 1 |
| 2.0a | 5 | 6.9 | 2.6% | 0 | 1 |
| 1.0b | 4 | 6.2 | 2.3% | 0 | 1 |