CVE-2024-58299: Pcman FTP Server

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.

Affected products

  • Pcman FTP Server: version 2.0 only

Published 2025-12-12. Last modified 2026-06-17.