Netwin SurgeFTP <= v23c8 Authenticated RCE
Vulnerability Description
Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via crafted POST requests to `surgeftpmgr.cgi`. This can lead to full remote code execution on the underlying system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10028
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Spencer McIntyre
References
Affected Vendor
Netwin
View all reports →