CVE-2006-4948

ProSysInfo TFTP Server TFTPDWIN <0.4.2 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2006-4948. PoCs published by Metasploit, SkD, Jacopo Cervini, including Metasploit module exploits/windows/tftp/tftpdwin_long_filename.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in ProSysInfo TFTPDWIN v0.4.2 by sending an overly long filename via UDP to port 69, overwriting the stack and executing arbitrary payloads. It uses a known return address (0x00458b91) in tftpd.exe for reliable exploitation.

Description

Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16346

This exploit targets a buffer overflow vulnerability in ProSysInfo TFTPDWIN v0.4.2 by sending an overly long filename via UDP to port 69, overwriting the stack and executing arbitrary payloads. It uses a known return address (0x00458b91) in tftpd.exe for reliable exploitation.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ProSysInfo TFTPDWIN v0.4.2
No auth needed
Prerequisites: Network access to the TFTP server (UDP port 69) · Target running vulnerable TFTPDWIN v0.4.2
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by SkD · perlremotewindows
https://www.exploit-db.com/exploits/7452

This exploit targets a buffer overflow vulnerability in ProSysInfo TFTP server TFTPDWIN <= 0.4.2. It sends a maliciously crafted UDP packet to port 69, triggering a remote code execution via shellcode that spawns a calculator (calc.exe).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ProSysInfo TFTP server TFTPDWIN <= 0.4.2
No auth needed
Prerequisites: Network access to the target's TFTP service (UDP port 69) · Vulnerable version of ProSysInfo TFTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Jacopo Cervini · perlremotewindows
https://www.exploit-db.com/exploits/3132

This exploit targets a buffer overflow vulnerability in TFTPD Win 0.4.2 via a maliciously crafted UDP packet. It includes shellcode to spawn a bind shell on port 4444, allowing remote command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: TFTPD Win 0.4.2
No auth needed
Prerequisites: Network access to the target's TFTPD service · UDP port 69 (or custom port) accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
by aushack · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/tftp/tftpdwin_long_filename.rb

This Metasploit module exploits a stack-based buffer overflow in ProSysInfo TFTPDWIN v0.4.2 by sending an overly long filename via UDP to port 69, allowing remote code execution. The exploit leverages a known return address (0x00458b91) in tftpd.exe to redirect execution to the payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ProSysInfo TFTPDWIN v0.4.2
No auth needed
Prerequisites: Network access to UDP port 69 on the target
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29075
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/29032
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20131
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3731
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21854

Scores

EPSS 0.5384
EPSS Percentile 98.9%

Details

Status published
Products (1)
prosysinfo/tftp_server_tftpdwin < 0.4.2
Published Sep 23, 2006
Tracked Since Feb 18, 2026