source: https://www.securityfocus.com/bid/9299/info
It has been reported that Surfboard httpd is prone to a remote buffer overflow condition that may allow an attacker to gain unauthorized access to a system running the vulnerable software. The issue presents itself when an attacker sends a specially crafted URL request with more than 1024 characters to the server daemon.
Surfboard version 1.1.9 has been reported to be prone to this issue, however, other versions may be affected as well.
GET /AAAAAAAAAAAA..x1024++ HTTP/1.1\r\n\r\n