CVE-2020-14057: Monstaftp Monsta FTP

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.

Affected products

  • Monstaftp Monsta FTP: up to and including 2.10.1

Published 2020-07-01. Last modified 2026-06-17.