PT-2026-2428 · Unknown · Tftpd32 Se
Ismael Nava
·
Published
2026-01-13
·
Updated
2026-01-14
·
CVE-2023-54338
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tftpd32 SE version 4.60
Description
The software contains an unquoted service path issue that may allow local attackers to execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with system-level permissions.
Recommendations
Update to a newer version that addresses this issue. As a temporary workaround, consider modifying the service configuration to use quoted paths to prevent the execution of unauthorized code.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tftpd32 Se