CVE-2019-25619: Ftpshell Server

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by supplying a crafted string. Attackers can inject shellcode through the account name parameter in the Manage FTP Accounts dialog to overwrite the return address and execute calc.exe or other commands.

Affected products

  • Ftpshell Ftpshell Server: version 6.83 only

Published 2026-03-22. Last modified 2026-06-17.