Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Xftp FTP Client Stack-Based Buffer Overflow Vulnerability via PWD Response

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Xftp FTP Client versions through 3.0 (build 0238). This vulnerability is triggered by a maliciously crafted PWD response from an FTP server. When the client receives an excessively long directory string in response to the PWD command, it fails to properly validate the input length before copying it into a fixed-size buffer. This oversight leads to memory corruption, allowing remote attackers to execute arbitrary code on the client system.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected client system.

Reproduction

The vulnerability can be reproduced by sending an overly long PWD response to the Xftp FTP client. This can be done by using an FTP server that responds to the PWD command with a directory string that exceeds the buffer size that Xftp can handle. The buffer overflow occurs when the client attempts to process this long response, leading to memory corruption and the potential execution of arbitrary code.

Added: Aug 21, 2025, 9:20 PM
Updated: Aug 21, 2025, 9:20 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
10.0
exploitability
6.4
remediation
0.0
relevance
0.4
threat
9.2
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.