SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash when submitting the registration code.
Cite this page
CVE-2019-25711. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2019-25711
Use CWE-807, Nsasoft vendor hub and Spotftp product page to widen CVE-2019-25711 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-37209 and CVE-2020-37208 for nearby disclosures in the same product family.