CVE-2023-53886: Xlightftpd Xlight FTP Server
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that allows attackers to crash the application. Attackers can trigger the vulnerability by inserting 294 characters into the program execution configuration, causing a denial of service condition.
Affected products
- Xlightftpd Xlight FTP Server: version 3.9.3.6 only
Published 2025-12-15. Last modified 2026-06-17.