CVE-2019-25614: Freefloat FTP Server
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.
Affected products
- Freefloat Freefloat FTP Server: version 1.0 only
Published 2026-03-22. Last modified 2026-06-17.