
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-37136 is a stack-based buffer overflow (denial of service) vulnerability in ZOC Terminal version 7.25.5, affecting the private key file input field used during SSH key file creation. An attacker can overwrite the private key file input with a 2000-byte buffer, causing the application to crash and become unresponsive. The vulnerability was formally published on February 5, 2026, and is assigned a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.7 (Medium) (VulnCheck Advisory, Exploit-DB).
The root cause is a stack-based buffer overflow (CWE-121) in ZOC Terminal's handling of the private key file input field. When a user attempts to create SSH key files, the application fails to properly validate the length of input supplied to the private key file field, allowing an oversized buffer (~2000 bytes) to overflow the stack and crash the process. The attack vector is local user interaction (the attacker must supply malicious input to the field), though the CVSS v3.1 vector rates it as network-accessible with no privileges required, reflecting the potential for a crafted file or remote scenario. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB, VulnCheck Advisory).
Successful exploitation results in a denial of service — the ZOC Terminal application crashes and becomes unresponsive, disrupting SSH session management and key file operations for the affected user. There is no known confidentiality or integrity impact; the vulnerability is limited to availability. The scope is confined to the local application instance, with no evidence of lateral movement potential or data exfiltration risk (VulnCheck Advisory).
A public proof-of-concept exploit has been available on Exploit-DB (EDB-ID 48292) since at least 2020, predating the formal CVE publication (Exploit-DB). The EPSS score is approximately 0.037%, indicating a low probability of active exploitation in the wild. There is no known threat actor attribution, no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (VulnCheck Advisory).
zoc.exe or zoc) terminates unexpectedly or becomes unresponsive during SSH key file creation..dmp files) generated by the OS in the user's temp directory or ZOC Terminal installation folder following the crash.No vendor patch or official advisory from EmTec has been identified for this specific vulnerability. Users should avoid entering untrusted or excessively long strings into the private key file input field in ZOC Terminal 7.25.5. Upgrading to the latest available version of ZOC Terminal from the vendor's website (https://www.emtec.com) is recommended, as newer versions may address this issue. Organizations should monitor the EmTec website for security updates (VulnCheck Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."