Security Advisory

CVE-2019-25614

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-22 13:38:46
Last updated 2026-03-23 15:29:55
Assigner VulnCheck
State PUBLISHED

Description

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.