
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-50689 is a local denial-of-service vulnerability in Cobian Reflector 0.9.93 RC1 caused by a buffer overflow in the SFTP password input field. An attacker with local access can paste an approximately 8,000-byte buffer into the password field during SFTP task configuration, causing the application to crash. The vulnerability was published on December 22, 2025, and assigned by VulnCheck. It carries a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (Feedly, VulnCheck).
The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input — 'Classic Buffer Overflow'). The application fails to validate or limit the length of user-supplied input in the SFTP password field, allowing an oversized input (~8,000 bytes) to overflow an internal buffer and crash the process. Exploitation requires local access to the system and the ability to interact with the Cobian Reflector GUI during SFTP task configuration. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB, VulnCheck).
Successful exploitation results in an application crash, disrupting availability of Cobian Reflector and preventing legitimate SFTP-based backup operations from running. There is no impact on confidentiality or integrity, as the vulnerability only affects availability. The scope is limited to the local system running the affected application, with no evidence of lateral movement potential (Feedly).
A proof-of-concept exploit is publicly available on Exploit-DB (EDB-50789), demonstrating the crash via an 8,000-byte password field input. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.011% (0.000110), indicating very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Exploit-DB, Feedly).
CobianReflector.exe crash or absence from the process list after being active).CobianReflector.exe with a faulting module related to a buffer overflow condition..dmp) in the application directory or %LOCALAPPDATA%\CrashDumps\ associated with the Cobian Reflector process.No official patch has been released for Cobian Reflector 0.9.93 RC1 as of the publication date. Users should upgrade to a version beyond 0.9.93 RC1 when a patched release becomes available from the vendor (CobianSoft). As an interim measure, restrict local access to systems running Cobian Reflector to trusted users only, since exploitation requires local interactive access. Monitor for unexpected application crashes as a detection measure (VulnCheck).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."