CVE-2020-37067 HIGH

CVE-2020-37067: Filetto 1.0 - 'FEAT' Denial of Service

Vendor Utillyty
Product Filetto
Weakness CWE-770 · Uncontrolled resource consumption
Published February 3, 2026
Last update February 4, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send an oversized FEAT command with 11,008 bytes of repeated characters to trigger a buffer overflow and terminate the FTP service.

Key dates

02Disclosure timeline

February 3, 2026 CVE published
February 4, 2026 Record updated