Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Southrivertech

First CVE: Feb 6, 2009Active for: 17 yearsTotal CVEs: 21
35.6
VTI Score
Medium

Southrivertech develops a focused portfolio of file-transfer and managed-file-transfer (MFT) server products, including Titan FTP Server, Titan SFTP Server, Titan MFT Server, and WebDrive, which are deployed in enterprise environments where secure data exchange is critical. The vendor's vulnerability exposure, while modest in volume, recurs through weakness classes characteristic of file-handling and protocol-parsing complexity: path-traversal flaws, code-injection conditions, improper parameter handling, and privilege-management gaps that reflect the server's role in authenticating and mediating access to shared resources. A notable share of disclosures acquire public exploit code, consistent with the appeal of file-transfer appliances as targets for lateral movement and data exfiltration. Defenders should monitor this vendor's advisories for path-traversal and authentication-bypass patterns, particularly where instances are internet-exposed or handle sensitive data; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Southrivertech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2009
17 years ago
Most Recent CVE
Mar 30, 2026
116 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-6082MEDIUM
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO command.
Feb 6, 20095.054NOYES
CVE-2023-22629HIGH
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authenticated attacker can upload any
Feb 14, 20238.852NOYES
CVE-2014-1843MEDIUM
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to obtain the property information of an arbitrary home f
Apr 29, 20145.037NOYES
CVE-2019-10009MEDIUM
A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandl
Jun 3, 20196.536NOYES
CVE-2014-1842MEDIUM
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to list all usernames via a Go action with a .. (dot dot)
Apr 29, 20145.033NOYES
CVE-2014-1841MEDIUM
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user's home folder via a Move action
Apr 29, 20145.033NOYES
CVE-2022-34005CRITICAL
An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Expr
Jun 19, 20229.831NONO
CVE-2023-45685CRITICAL
Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker to wr
Oct 16, 20239.128NONO
CVE-2023-45687HIGH
A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the server's authentication if they
Oct 16, 20238.825NONO
CVE-2023-27745HIGH
An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform Administrative actions by sending requests to the user server
Jun 2, 20238.825NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
62%
29%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (19.0%)
Network11 (52.4%)
Unknown6 (28.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (71.4%)
High0 (0.0%)
Unknown6 (28.6%)
User Interaction
None13 (61.9%)
Unknown6 (28.6%)
Required2 (9.5%)
Privileges Required
Low7 (33.3%)
High4 (19.0%)
None4 (19.0%)
Unknown6 (28.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
9.5% of CVEs· 98th percentile
Nuclei
4 CVEs
19.0% of CVEs· 97th percentile
ExploitDB
6 CVEs
28.6% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Southrivertech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Southrivertech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Southrivertech's Products

View all 4 CNAs →

Top CWEs