Troglobit maintains a narrow portfolio of small, specialized utilities and libraries—notably the uftpd FTP daemon, libeuv event library, and pimd multicast daemon—that serve critical roles in embedded and legacy systems where they often persist with minimal oversight. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, driven by recurring memory-safety and file-access weaknesses including buffer overflows, path-traversal conditions, link-following flaws, NULL-pointer dereferences, and out-of-bounds writes that are characteristic of C-based system software. These weakness classes and the vendor's focus on foundational network and protocol services make this vendor's advisories relevant to defenders managing embedded infrastructure and legacy deployments; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Troglobit over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-20277CRITICAL There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot | Dec 18, 2020 | 9.8 | 54 | NO | YES |
CVE-2020-20276CRITICAL An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potent | Dec 18, 2020 | 9.8 | 29 | NO | NO |
CVE-2022-48620CRITICAL uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number. | Jan 12, 2024 | 9.8 | 26 | NO | NO |
CVE-2020-5221HIGH In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locat | Jan 22, 2020 | 7.2 | 23 | NO | NO |
CVE-2020-5204HIGH In uftpd before 2.11, there is a buffer overflow vulnerability in handle_PORT in ftpcmd.c that is caused by a buffer that is 16 bytes large being filled via sprintf() with user inp | Jan 6, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-14149HIGH In uftpd before 2.12, handle_CWD in ftpcmd.c mishandled the path provided by the user, causing a NULL pointer dereference and denial of service, as demonstrated by a CWD /.. comman | Jun 15, 2020 | 7.5 | 20 | NO | NO |
pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary files via a symlink attack on (1) pimd.dump when a USR1 signal is sent, or (2) pimd | Jan 11, 2011 | 3.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Troglobit.
Media articles that mention a CVE ID that affects a product developed by Troglobit — matched by CVE ID, not by vendor name.