A critical security vulnerability, tracked as CVE-2025-34299, was discovered in Monsta FTP versions 2.11 and earlier, allowing unauthenticated attackers to upload arbitrary files to affected servers. This flaw enables remote code execution (RCE) without requiring any authentication, as attackers can trick the application into downloading and saving malicious files from attacker-controlled (S)FTP servers directly onto the victim’s system. The vulnerability was identified by cybersecurity researchers at watchTowr, who confirmed that the exploit could be used to gain full control over targeted web servers running vulnerable versions of Monsta FTP.
Monsta FTP is widely used for web-based file management by organizations ranging from financial institutions to individual website owners, increasing the potential impact of this vulnerability. Security advisories emphasize the critical nature of the flaw, with a CVSS score of 9.3, and recommend immediate patching or mitigation to prevent exploitation. The vulnerability is pre-authentication, meaning attackers do not need valid credentials to exploit it, making unpatched systems especially susceptible to takeover and compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
runZero published technical guidance on how defenders can find Monsta FTP installations on their networks. The post represented a defensive response to help organizations assess exposure to the vulnerable software.
Public reporting highlighted that the Monsta FTP vulnerability exposed thousands of web servers and could be leveraged for full server takeover. This marked broader awareness of the scale and impact of the flaw.
A high-severity vulnerability, CVE-2025-34299, was disclosed affecting Monsta FTP versions 2.11 and earlier. The issue allows unauthenticated arbitrary file upload, creating a path to possible server compromise.
3 references tracked. Mallory keeps watching after this page renders.
runzero.com
Open sourcehackread.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.