LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2019-25614

CVE-2019-25614 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 22, 2026

Free Float FTP - Buffer Overflow

Published: March 22, 2026Updated: March 22, 2026Remote Exploitable

Overview

Free Float FTP 1.0 contains a buffer overflow caused by an oversized payload in the STOR command handler, letting remote attackers execute arbitrary code, exploit requires anonymous authentication.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Remote attackers can execute arbitrary code on the FTP server, potentially leading to full system compromise.

Mitigation

Update to the latest version of Free Float FTP.

Details

CVE ID
CVE-2019-25614
Severity
Critical
CVSS Score
9.8
Type
buffer_overflow
Status
new

CWE

  • CWE-787

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H