CVE-2018-25254

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nico-ftp_project:nico-ftp:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-04 14:16

Updated : 2026-07-24 22:10


NVD link : CVE-2018-25254

Mitre link : CVE-2018-25254

CVE.ORG link : CVE-2018-25254


JSON object : View

Products Affected

nico-ftp_project

  • nico-ftp
CWE
CWE-787

Out-of-bounds Write