Nsasoft Backup Key Recovery Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Nsasoft Backup Key Recovery version 2.2.5. This vulnerability allows attackers to crash the application by entering an excessively long registration key. By generating a payload file with 1000 characters and pasting it into the registration key field, the application can be made to crash.

Impact

Exploitation of this vulnerability leads to a crash of the Backup Key Recovery application, causing a denial-of-service condition.

Reproduction

To reproduce this vulnerability, download and install Backup Key Recovery version 2.2.5. After installation, run a Python script that creates a 1000-character payload file named 'poc.txt'. Open the Backup Key Recovery application and navigate to the registration section. Copy the payload from 'poc.txt' and paste it into the 'Key' registration field. Click 'Ok' to submit. The application will crash, demonstrating the denial-of-service vulnerability.

Added: Feb 11, 2026, 9:43 PM
Updated: Feb 11, 2026, 9:43 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.6
remediation
0.0
relevance
2.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.