CVE-2022-50689

MEDIUM

Cobian Reflector 0.9.93 RC1 - DoS

Title source: llm

Description

Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can paste a large 8000-byte buffer into the password field to trigger an application crash during SFTP task configuration.

Exploits (1)

exploitdb WORKING POC
by Luis Martínez · pythonlocalwindows
https://www.exploit-db.com/exploits/50789

Scores

CVSS v3 6.2
EPSS 0.0003
EPSS Percentile 7.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-120
Status published
Products (1)
cobiansoft/reflector 0.9.93 rc1
Published Dec 22, 2025
Tracked Since Feb 18, 2026