Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Troglobit

First CVE: Jan 11, 2011Active for: 16 yearsTotal CVEs: 7

Troglobit maintains a narrow portfolio of small, specialized utilities and libraries—notably the uftpd FTP daemon, libeuv event library, and pimd multicast daemon—that serve critical roles in embedded and legacy systems where they often persist with minimal oversight. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, driven by recurring memory-safety and file-access weaknesses including buffer overflows, path-traversal conditions, link-following flaws, NULL-pointer dereferences, and out-of-bounds writes that are characteristic of C-based system software. These weakness classes and the vendor's focus on foundational network and protocol services make this vendor's advisories relevant to defenders managing embedded infrastructure and legacy deployments; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 11% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Troglobit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 11, 2011
15 years ago
Most Recent CVE
Jan 12, 2024
924 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-20277CRITICAL
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot
Dec 18, 20209.854NOYES
CVE-2020-20276CRITICAL
An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potent
Dec 18, 20209.829NONO
CVE-2022-48620CRITICAL
uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.
Jan 12, 20249.826NONO
CVE-2020-5221HIGH
In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locat
Jan 22, 20207.223NONO
CVE-2020-5204HIGH
In uftpd before 2.11, there is a buffer overflow vulnerability in handle_PORT in ftpcmd.c that is caused by a buffer that is 16 bytes large being filled via sprintf() with user inp
Jan 6, 20208.822NONO
CVE-2020-14149HIGH
In uftpd before 2.12, handle_CWD in ftpcmd.c mishandled the path provided by the user, causing a NULL pointer dereference and denial of service, as demonstrated by a CWD /.. comman
Jun 15, 20207.520NONO
CVE-2011-0007LOW
pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary files via a symlink attack on (1) pimd.dump when a USR1 signal is sent, or (2) pimd
Jan 11, 20113.314NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
43%
43%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowHighCritical
Attack Vector
Local0 (0.0%)
Network6 (85.7%)
Unknown1 (14.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High0 (0.0%)
Unknown1 (14.3%)
User Interaction
None6 (85.7%)
Unknown1 (14.3%)
Required0 (0.0%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None5 (71.4%)
Unknown1 (14.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Troglobit.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Troglobit — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Troglobit's Products

View all 3 CNAs →

Top CWEs