CVE-2019-25361: Ayukov Nftp Client
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted SYST command with oversized payload to trigger a buffer overflow and execute a bind shell on port 5150.
Affected products
- Ayukov Ayukov Nftp Client: version 1.71 only
Published 2026-02-18. Last modified 2026-06-17.