Stack-Based Buffer Overflow in EasyFTP Server by EasyFTP
CVE-2010-20121
Key Information:
- Vendor
Kmint21 Software
- Status
- Vendor
- CVE Published:
- 21 August 2025
Badges
What is CVE-2010-20121?
EasyFTP Server versions up to 1.7.0.11 are susceptible to a stack-based buffer overflow in the FTP command parser, specifically when handling the CWD (Change Working Directory) command. The server insufficiently validates the length of the input string, allowing attackers to overwrite memory on the stack. This leads to the potential for remote code execution without requiring authentication, as the server permits anonymous access by default. The issue was addressed in version 1.7.0.12, which afterwards rebranded the product as UplusFtp.
Affected Version(s)
EasyFTP Server * <= 1.7.0.11
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved