CVE-2023-24042: HFIREF0X Lightftp

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName.

Affected products

  • HFIREF0X Lightftp: up to and including 2.2

Published 2023-01-21. Last modified 2026-06-17.