CVE-2019-25332: Internet-Soft FTP Commander Pro

High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.

FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting the EIP register through a custom command input. Attackers can craft a malicious payload of 4108 bytes to overwrite memory and execute shellcode, demonstrating remote code execution potential.

Affected products

  • Internet-Soft FTP Commander Pro: version 8.02 only; version 8.03 only

Published 2026-02-12. Last modified 2026-06-17.