Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

FTPPad Stack-Based Buffer Overflow Vulnerability

Vulnerability

A stack-based buffer overflow vulnerability has been identified in FTPPad versions through 1.2.0. This vulnerability arises in the FTP directory listing parser, where the application fails to properly validate the length of directory and filename data received in response to a LIST command. As a result, remote attackers can craft responses that include excessively long filenames, leading to a buffer overflow. This overflow overwrites the saved Extended Instruction Pointer (EIP), allowing for the execution of arbitrary code.

Impact

Exploitation of this vulnerability causes a stack-based buffer overflow, which can be leveraged to execute arbitrary code on the affected system.

Reproduction

The vulnerability can be reproduced by using a custom-built FTP client fuzzer, which is available as a Metasploit module. This fuzzer sends overly long directory listings to the FTPPad client, triggering the buffer overflow. The Metasploit module handles the exploitation by establishing a data connection and sending a crafted directory listing that includes the payload, which is then executed by the application.

Added: Aug 21, 2025, 9:26 PM
Updated: Aug 21, 2025, 9:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.1
remediation
0.0
relevance
0.4
threat
8.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.