CVE-2024-58299

Severity CVSS v4.0:
CRITICAL
Type:
CWE-121 Stack-based Buffer Overflow
Publication date:
12/12/2025
Last modified:
12/12/2025

Description

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.