Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Odin Secure FTP Stack-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Odin Secure FTP versions through 4.1. This issue arises when the client processes directory listings received in response to an FTP LIST command. A malicious FTP server can exploit this vulnerability by sending an excessively long filename, which overflows a fixed-size stack buffer in the client. This overflow overwrites the Structured Exception Handler (SEH) record, potentially allowing remote attackers to execute arbitrary code on the affected system.

Impact

Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution on the client system.

Reproduction

The vulnerability can be reproduced by using an FTP server to send a directory listing response that includes a filename longer than what the client can safely process. This can be done by using the Metasploit Framework's FTP fuzzer module to automate the process of sending long filenames in response to FTP commands.

Added: Aug 20, 2025, 4:41 PM
Updated: Aug 20, 2025, 4:41 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
9.1
remediation
0.0
relevance
0.4
threat
9.3
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.