CVE-2019-25614 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 22, 2026
Free Float FTP - Buffer Overflow
Published: March 22, 2026Updated: March 22, 2026Remote Exploitable
Overview
Free Float FTP 1.0 contains a buffer overflow caused by an oversized payload in the STOR command handler, letting remote attackers execute arbitrary code, exploit requires anonymous authentication.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Remote attackers can execute arbitrary code on the FTP server, potentially leading to full system compromise.
Mitigation
Update to the latest version of Free Float FTP.
References
Related Resources
Details
- CVE ID
- CVE-2019-25614
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- buffer_overflow
- Status
- new
CWE
- CWE-787
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H