Local Stack Overflow Vulnerability in FTP Commander Pro by Internet Soft
CVE-2019-25332
Key Information:
- Vendor
Internet-soft
- Status
- Vendor
- CVE Published:
- 12 February 2026
Badges
What is CVE-2019-25332?
The FTP Commander Pro version 8.03 is vulnerable to a local stack overflow issue that can allow attackers to execute arbitrary code. By providing a carefully crafted input of 4108 bytes, an attacker can overwrite the EIP register, enabling remote code execution. This vulnerability poses a serious risk, as it allows for the execution of shellcode, making it essential for users to apply security measures and updates promptly.
Affected Version(s)
FTP Commander Pro 8.02
FTP Commander Pro 8.03
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
