CVE-2019-25614

Severity CVSS v4.0:
CRITICAL
Type:
CWE-787 Out-of-bounds Write
Publication date:
22/03/2026
Last modified:
23/03/2026

Description

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:freefloat:freefloat_ftp_server:1.0:*:*:*:*:*:*:*