CVE-2025-34107: Labf Winaxe FTP Client

High severity, CVSS 8.7. EPSS: 1.2% chance of exploitation in the next 30 days.

A buffer overflow vulnerability exists in the WinaXe FTP Client version 7.7 within the FTP banner parsing functionality, WCMDPA10.dll. When the client connects to a remote FTP server and receives an overly long '220 Server Ready' response, the vulnerable component responsible for parsing the banner overflows a stack buffer, leading to arbitrary code execution under the context of the user.

Affected products

  • Labf Winaxe FTP Client: version 7.7 only

Published 2025-07-15. Last modified 2026-06-17.