CVE-2019-25614 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 23, 2026
Free Float FTP - Buffer Overflow
Published: March 22, 2026Updated: March 23, 2026PoC AvailableRemote Exploitable
Overview
Free Float FTP 1.0 contains a buffer overflow caused by an oversized payload in the STOR command handler, letting remote attackers execute arbitrary code, exploit requires anonymous authentication.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Remote attackers can execute arbitrary code on the FTP server, potentially leading to full system compromise.
Mitigation
Update to the latest version of Free Float FTP.
References
Related Resources
Details
- CVE ID
- CVE-2019-25614
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- buffer_overflow
- Status
- confirmed
CWE
- CWE-787
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H