PT-2026-2428 · Unknown · Tftpd32 Se

Ismael Nava

·

Published

2026-01-13

·

Updated

2026-01-14

·

CVE-2023-54338

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tftpd32 SE version 4.60
Description The software contains an unquoted service path issue that may allow local attackers to execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with system-level permissions.
Recommendations Update to a newer version that addresses this issue. As a temporary workaround, consider modifying the service configuration to use quoted paths to prevent the execution of unauthorized code.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-54338

Affected Products

Tftpd32 Se