CVE-2018-25254: Nico-FTP Project Nico-FTP
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.
Affected products
- Nico-FTP Project Nico-FTP: up to and including 3.0.1.19
Published 2026-04-04. Last modified 2026-10-06.