NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Surgeftp | Netwin | 2.0a (including) | 2.0a (including) |
| Surgeftp | Netwin | 2.0b (including) | 2.0b (including) |
| Surgeftp | Netwin | 2.0c (including) | 2.0c (including) |
| Surgeftp | Netwin | 2.0d (including) | 2.0d (including) |
| Surgeftp | Netwin | 2.0e (including) | 2.0e (including) |
| Surgeftp | Netwin | 2.0f (including) | 2.0f (including) |