


Perceptive Security
SOC/SIEM Consultancy

Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send …
Published:
2 February 2026 at 23:00:00
Alert date:
3 February 2026 at 23:08:48
Source:
nvd.nist.gov
Network Infrastructure
CVE-2020-37067 affects Filetto 1.0 FTP server, containing a denial of service vulnerability in the FEAT command processing. Attackers can exploit this by sending an oversized FEAT command with 11,008 bytes of repeated characters, triggering a buffer overflow that crashes the FTP service. This is a classic buffer overflow vulnerability that allows remote attackers to terminate the service availability. The vulnerability has been documented with proof-of-concept exploits available on Exploit-DB. The issue affects the command processing functionality of the FTP server, making it susceptible to denial of service attacks through malformed FEAT commands.
Technical details
Mitigation steps:
Affected products:
Filetto FTP Server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2020-37067
http://www.utillyty.eu
https://sourceforge.net/projects/filetto
https://www.exploit-db.com/exploits/48503
https://www.vulncheck.com/advisories/filetto-feat-denial-of-service
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
