Buffer Overflow Vulnerability in FreeFloat FTP Server
CVE-2025-5074
Key Information:
- Vendor
Freefloat
- Status
- Vendor
- CVE Published:
- 22 May 2025
Badges
What is CVE-2025-5074?
A significant buffer overflow vulnerability has been identified in the PROMPT Command Handler of FreeFloat FTP Server 1.0. This flaw allows an attacker to manipulate the command handler remotely, potentially leading to unauthorized access or system compromise. Given that the exploit code is publicly disclosed, organizations using this server are strongly advised to assess their security posture and implement necessary patches or workarounds to mitigate the risks associated with this vulnerability.
Affected Version(s)
FTP Server 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved