CVE-2018-25229: Bpftpserver Bulletproof FTP Server

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the SMTP configuration interface that allows local attackers to crash the application by supplying an oversized string. Attackers can input a buffer of 257 'A' characters in the SMTP Server field and trigger a crash by clicking the Test button.

Affected products

  • Bpftpserver Bulletproof FTP Server: version 2019.0.0.50 only

Published 2026-03-30. Last modified 2026-06-17.