VulnerabilitiesCritical

CVE-2019-25614: High Severity Vulnerability Disclosed

Monday, March 23, 2026
Global
NVD - CVE-2019-25614

Summary

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous cred

Threat Analysis

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server. This vulnerability has been assigned a CVSS score of 9.8, indicating critical severity. Organizations using affected products should review vendor advisories and apply patches as soon as they become available. Mitigation: Monitor vendor security bulletins, implement defense-in-depth strategies, and conduct vulnerability assessments regularly.

Last updated: Mar 23, 2026, 01:18 PM

Daily Intelligence

Stay Ahead of Threats

Subscribe to receive daily threat briefings delivered to your inbox. Be the first to know about emerging security risks.

No spamUnsubscribe anytimeDaily at 9 AM