Denial of Service Vulnerability in BulletProof FTP Server by BulletProof
CVE-2019-25588
Key Information:
- Vendor
Bpftpserver
- Status
- Vendor
- CVE Published:
- 22 March 2026
Badges
What is CVE-2019-25588?
The BulletProof FTP Server 2019.0.0.50 is susceptible to a denial of service vulnerability that can be exploited by local attackers. By injecting an excessively long string into the DNS Address field, an attacker can trigger a crash of the application. This vulnerability can be exploited when the attacker enables the DNS Address option in the Firewall settings and invokes the Test function, which processes the input. The malicious input, with a buffer length of 700 bytes or more, can lead to an application crash, disrupting service availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BulletProof FTP Server 2019.0.0.50
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
