Two FTP server products were disclosed with serious buffer overflow vulnerabilities that can be triggered remotely. Core FTP/SFTP Server 1.2 is affected by CVE-2019-25654, a flaw in the User domain field where an excessively long string of roughly 7,000 bytes can crash the application and cause a denial of service. The issue is classified as CWE-120/buffer overflow behavior with impact focused on availability, and public references include advisories from VulnCheck and Exploit-DB.
A separate flaw, CVE-2018-25254, affects NICO-FTP 3.0.1.19 and is described as a remote SEH buffer overflow reachable through crafted FTP commands containing oversized data. The vulnerability allows unauthenticated attackers to overwrite exception handler pointers and potentially execute injected shellcode, leading to full remote code execution with high impact on confidentiality, integrity, and availability. The disclosures highlight continued risk from legacy FTP software that processes untrusted input without proper bounds checking.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A new CVE entry documented a remotely exploitable SEH buffer overflow in NICO-FTP 3.0.1.19, where crafted oversized FTP command data can let an unauthenticated attacker overwrite SEH pointers and achieve arbitrary code execution. The record was received by disclosure@vulncheck.com and includes references to advisory and exploit sources.
A CVE record was received documenting a buffer overflow in Core FTP/SFTP Server 1.2 that can be triggered with an excessively long User domain string, causing the application to crash and resulting in denial of service. The record notes receipt by disclosure@vulncheck.com and references supporting advisories and exploit material.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.