CVE-2025-5548 is a remotely exploitable buffer overflow vulnerability in FreeFloat FTP Server 1.0. The issue affects an unspecified function in the server's NOOP command handler. A crafted NOOP request can trigger memory corruption due to improper bounds handling, resulting in a classic buffer overflow condition. Public reporting indicates the flaw is reachable over the network and does not require privileges or user interaction. Public exploit information has been disclosed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
10 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (24 hidden).
This repository is a lab-oriented exploit-development project for FreeFloat FTP Server 1.0 targeting CVE-2025-5548, a classic stack-based buffer overflow in the FTP NOOP command handler caused by unsafe strcpy-style copying into a fixed-size stack buffer. The repo is not a polished weaponized exploit; instead it documents the full workflow from environment setup and root-cause analysis through practical exploitation. Structure: the repository contains mostly Markdown documentation plus six Python scripts under 02-Exploitation/exploit/. README.md and METHODOLOGY.md explain the author’s general vulnerability-analysis process. 00-Environment/ describes the intended lab topology: attacker machine with Python/msfvenom/netcat and a Windows victim running FreeFloat FTP 1.0 under Immunity Debugger. 01-Vulnerability-Analysis/ explains the bug pattern in the binary and notes similar unsafe handlers for other FTP commands. 02-Exploitation/ maps each exploitation phase to a dedicated script. 03-0day-Approach/ is methodological background on fuzzing, diffing, and reversing. Exploit capabilities: the Python code performs staged network exploitation over FTP on TCP/21. 01_handshake.py validates connectivity and anonymous login. 02_crash_finder.py sends progressively larger NOOP arguments to identify a crash threshold. 03_offset_finder.py generates and sends a cyclic pattern, then computes the EIP overwrite offset from a debugger-observed value. 04_eip_control.py verifies instruction-pointer control with a BBBB marker. 05_bad_chars.py sends nearly the full byte range after the overwrite point to identify disallowed bytes. 06_final_exploit.py builds the final payload using attacker-supplied offset, pivot address, NOP sled, and shellcode. The documented intended payload is msfvenom-generated windows/shell_reverse_tcp shellcode, but the repository leaves the actual shellcode and target-specific values blank. Notable limitations: all critical operational values are placeholders (TARGET_IP, OFFSET, PIVOT_ADDRESS, SHELLCODE), so the repository is best classified as a proof of concept and exploit-development template rather than a ready-to-run exploit. Still, it is clearly exploit code rather than a detector, because its purpose is to trigger the overflow and ultimately execute arbitrary shellcode on the vulnerable FTP service.
This repository is a documentation-focused proof-of-concept for CVE-2025-5548 affecting FreeFloat FTP Server 1.0 on Windows. It does not contain runnable exploit source code; instead, it walks through the full lab process in Markdown: environment preparation, binary analysis, and controlled exploitation. The analysis identifies the FTP USER command handler as the vulnerable path and attributes the flaw to unsafe use of strcpy in function sub_402190. The exploitation notes describe network-based triggering over FTP on TCP/21, fuzzing with progressively larger USER inputs, observing a crash in Immunity Debugger, using Mona to generate a cyclic pattern, and determining that EIP is overwritten at offset 246. A final validation step shows controlled EIP overwrite with 0x42424242. Repository structure is minimal: README.md provides the project overview, while Laboratory/environment.md documents tool installation and lab setup, Laboratory/analysis.md covers static/dynamic reverse engineering of FTPServer.exe, and Laboratory/explotation.md documents the buffer overflow workflow. Overall, the repository’s purpose is educational and reproducible exploit development guidance for a classic stack buffer overflow, culminating in instruction-pointer control but not a weaponized payload or shellcode stage.
This repository is a small exploit-development lab rather than a single polished exploit. It contains 10 files total: 3 Markdown documentation files and 7 Python scripts. The documentation is split into environment setup and exploitation methodology, while the scripts implement each stage of a classic stack-based buffer overflow workflow against FreeFloat FTP Server 1.0. The exploit path is entirely network-based and targets an FTP service on 127.0.0.1:21. Every script connects over TCP, receives the FTP banner, authenticates with 'USER anonymous' and 'PASS anonymous', and then abuses the FTP 'NOOP' command as the overflow vector. The repository repeatedly states that the target is used in a controlled educational environment. Repository structure and purpose: - README.md: high-level overview of the lab, goals, and structure. - environment/README.md: describes the tooling used, including Python, Immunity Debugger, Mona, Ghidra, IDA, Vulnserver, FreeFloat FTP Server, and ncat. - exploitation/README.md: explains the exploitation workflow from fuzzing to shellcode execution, including the discovered EIP offset of 246 bytes and the use of debugger-assisted gadget discovery. - scripts/01Python3Connection.py: simple connectivity and FTP command test. - scripts/02Python3Fuzzing.py: incrementally increases the size of the NOOP argument to identify the crash point. - scripts/03Python3EIPOffsetDiscovery.py: sends a cyclic pattern to determine the exact EIP overwrite offset. - scripts/04Python3ControlEIP.py: verifies EIP control using 246 'A' bytes followed by 'BBBB'. - scripts/05Python3FindBadChars.py: sends a full byte array after the EIP overwrite to identify bad characters; the docs note at least '\x00' is bad. - scripts/06Python3JMPESP.py: replaces EIP with a debugger-found address that redirects execution to ESP, followed by NOPs and INT3 bytes to confirm control flow. - scripts/07Python3Shellcode.py: final exploit stage that swaps the debug bytes for real shellcode and attempts arbitrary code execution. Main exploit capabilities: - Verifies target reachability and FTP interaction. - Fuzzes the vulnerable command to trigger a crash. - Discovers and validates the exact EIP overwrite offset (246 bytes). - Tests for bad characters in the payload path. - Redirects execution to attacker-controlled stack memory using a hardcoded gadget address found during debugging. - Delivers embedded shellcode for code execution. Important operational details: - The exploit is not framework-based. - It is operational as a lab exploit, but reliability depends on the exact debugging session and memory layout because the EIP overwrite addresses are hardcoded and differ between scripts 06 and 07. - The repository does not clearly document what the final shellcode does beyond demonstrating successful execution, so the post-exploitation effect is unspecified. - The code is clearly intended for local lab use, as all scripts target 127.0.0.1 and rely on a debugger-assisted workflow rather than a portable, one-click exploit.
This repository is a hands-on exploit-development lab for CVE-2025-5548, described here as a remote stack-based buffer overflow in FreeFloat FTP Server 1.0 triggered through the FTP NOOP command. The repo is not a framework module; it is a standalone educational project combining walkthrough documentation, screenshots, environment setup automation, and a sequence of Python proof-of-concept exploit scripts. Repository structure: the top-level README summarizes the project; Environment/README.md documents the Windows 11 lab and manual tool installation; exploitation/README.md provides the full methodology and attack chain; Images/ contains step-specific screenshot documentation; resources/ contains setup scripts for Linux and Windows plus the actual exploit scripts under resources/exploit/. Of 19 files, 9 are code or script files, primarily Python, Bash, and PowerShell. Main exploit capability: the Python scripts implement the classic buffer-overflow workflow against an FTP service on 127.0.0.1:21. 01Python3Connection.py validates connectivity and anonymous login, then sends NOOP test. 02Python3Fuzzing.py repeatedly sends larger NOOP buffers to crash the service. 03Python3EIPOffsetDiscovery.py sends a cyclic pattern to determine the overwrite offset. 04Python3ControlEIP.py confirms EIP control using 246 bytes of padding plus BBBB. 05Python3FindBadChars.py appends the full byte range after the overwrite to identify bad characters. 06Python3JMPESP.py replaces EIP with a hardcoded gadget address and uses NOPs/INT3 bytes to verify execution reaches attacker-controlled stack memory. 07Python3Shellcode.py delivers the final payload: 246-byte padding, a hardcoded EIP overwrite, a NOP sled, and embedded Windows shellcode. Targeting and assumptions: the exploit targets FreeFloat FTP Server 1.0 on Windows, listening on TCP/21, and assumes anonymous FTP login is possible. The walkthrough explicitly states the exploit is demonstrated in a debugger because ASLR and modern Windows mitigations make stable gadget selection difficult; therefore the hardcoded EIP overwrite addresses appear session-specific and are likely only reliable in the documented lab/debug context. Notable endpoints: the exploit code itself consistently targets 127.0.0.1:21. Additional fingerprintable artifacts include the Immunity Debugger PyCommands path used for mona.py and numerous external tool download URLs in the environment setup scripts. These setup scripts are ancillary and intended to build the lab, not to exploit the target. Overall assessment: this is a real exploit-development repository, not merely a detector or README. It is best classified as OPERATIONAL: it includes a working exploit chain and embedded shellcode, but the payload and gadget addresses are hardcoded and tailored to the author’s lab rather than generalized for broad reuse.
This repository is a documentation-heavy walkthrough for controlled exploitation of CVE-2025-5548 in FreeFloat FTP Server 1.0 rather than a complete exploit implementation. The repository contains 13 files, mostly Markdown documentation, with only two Python script files present in the provided archive and both effectively empty placeholders. The README and docs describe a classic Windows network buffer-overflow workflow against an FTP service: environment setup, vulnerability analysis, crash reproduction, offset discovery, EIP control validation, bad-character analysis, and eventual final exploit construction. The documented exploit capability is remote delivery of an oversized FTP command argument to the vulnerable FreeFloat FTP Server 1.0 service, causing a reproducible crash and overwrite of EIP. The walkthrough explicitly states that EIP is overwritten with 41414141 during initial testing, that a cyclic pattern yields EIP value 41326941, and that Mona calculates the exact offset to EIP as 246 bytes. A later validation shows EIP = 42424242, confirming attacker control of the instruction pointer. The bad-character analysis is preliminary and identifies 00 and 01 as problematic bytes. No final shellcode, ROP chain, return address, or working end-to-end exploit payload is included in the provided content, so the repository is best classified as a POC-level exploit-development walkthrough. Structurally, the repository is intended to include docs/, scripts/, images/, and notes/ directories. However, many referenced files are absent or empty in the provided archive, including the later-stage exploit scripts mentioned in the README (03_badchars.py, 04_eip_control.py, 05_final_exploit.py, requirements.txt). As provided, the main value is the methodology and extracted exploitation parameters, not executable exploit code. The primary attack vector is network-based over FTP to a Windows-hosted FreeFloat FTP Server 1.0 instance in a lab environment.
This repository is a small exploit-development lab rather than a single polished exploit. It contains 11 files total, with 7 Python scripts under 02Explotation/scripts and Markdown documentation in the root and 01Lab/ and 02Explotation/ directories. The overall purpose is to document and automate the classic workflow for developing a stack-based buffer overflow exploit against Free Float FTP Server on Windows, specifically through the FTP NOOP command on TCP port 21. Repository structure and purpose: - README.md: minimal top-level project label referencing CVE-2025-5548. - 01Lab/config_lab.md: lab setup guide for Windows exploit development tools such as Python, Java, Immunity Debugger, Mona, Ghidra, IDA, Nmap/Ncat, Git, and two target applications (Vulnserver and Free Float FTP Server). - 02Explotation/README.md: detailed exploitation methodology. It explains the vulnerable surface (NOOP), crash threshold, offset calculation, bad character discovery, gadget hunting, and payload generation with msfvenom. - 02Explotation/scripts/: sequential Python scripts implementing each stage of the exploit chain. Main exploit capabilities by script: 1. 01Python3Connection.py: basic FTP connectivity and command interaction using USER anonymous, PASS anonymous, and NOOP test. 2. 02Python3Fuzzing.py: repeatedly sends increasing NOOP payload sizes to identify the crash point. 3. 03Python3EIPOffsetDiscovery.py: sends a cyclic pattern to determine the exact EIP overwrite offset. 4. 04Python3ControlEIP.py: attempts to verify EIP control with 246 bytes of padding and a 4-byte marker. Note: the script contains a likely typo (`B'C' * 100`) that would prevent execution as written. 5. 05Python3FindBadChars.py: sends a full bytearray after the EIP overwrite to identify bad characters. 6. 06Python3JMPESP.py: overwrites EIP with a debugger-derived address intended to redirect execution to ESP, followed by NOPs and INT3 bytes for debugging. 7. 07Pyhton3Shellcode.py: final exploit form, delivering an EIP overwrite, NOP sled, and embedded x86 shellcode. Exploit logic extracted from the code and docs: - Attack vector: remote network exploitation over FTP. - Authentication flow: the scripts log in with anonymous credentials before sending the malicious NOOP command. - Vulnerable command: `NOOP`. - Crash threshold from documentation: around 400 bytes. - EIP offset: 246 bytes. - Bad characters: `\x00\x0a\x0d`. - Control-flow redirection: overwrite EIP with a fixed address intended to execute `JMP ESP`/`CALL ESP` during a debugger session. - Final stage: execute arbitrary shellcode from the stack. The documentation explicitly states the intended payload is a reverse shell generated with msfvenom for callback to 192.168.194.129:443. Notable observations: - The repository is a real exploit-development walkthrough, not just detection logic. - It is not part of a framework like Metasploit or Nuclei. - The included final shellcode is embedded and operational, but the return address appears debugger/session-specific, so reliability outside the described lab may be limited. - There is a discrepancy between the README's JMP ESP address (`0x74b6afa3`) and the scripts' overwrite bytes (`\x73\xaf\xb6\x74`, i.e. 0x74b6af73 little-endian). This suggests either a typo or a changed gadget during testing. - The claimed CVE identifier appears to be used as a project label; the actual technical target described in the code is Free Float FTP Server's NOOP buffer overflow.
This repository is a small educational exploit lab for CVE-2025-5548 against FreeFloat FTP Server 1.0 on Windows. It is not part of a larger exploit framework. The repo contains 7 Python scripts and 4 markdown documents that together walk through vulnerability analysis, debugger setup, and exploit development. Repository structure and purpose: - README.md indexes the lab and points to environment setup, analysis, and exploitation notes. - lab/entorno.md documents the Windows lab environment: Python, Nmap, Immunity Debugger, IDA Free, Mona, and the vulnerable FreeFloat FTP Server binary. - lab/analisis.md describes reverse-engineering steps to locate the vulnerable code path, identifying a crash around strcpy associated with FTP command handling. - lab/explotacion.md explains the exploit-development workflow using Mona and msfvenom. - scripts/01-07 are a linear progression from connectivity testing to final shellcode execution. Main exploit capabilities by script: 1. scripts/01Python3Connection.py: basic FTP connectivity and protocol interaction. Connects to 127.0.0.1:21, reads the banner, sends USER anonymous, PASS anonymous, and a benign NOOP test. 2. scripts/02Python3Fuzzing.py: repeatedly sends larger NOOP arguments to determine the approximate crash length for the vulnerable command handler. 3. scripts/03Python3EIPOffsetDiscovery.py: sends a cyclic pattern through the NOOP command to identify the exact EIP overwrite offset. 4. scripts/04Python3ControlEIP.py: sends 246 bytes plus BBBB to confirm control of EIP. 5. scripts/05Python3FindBadChars.py: appends a full bytearray after the EIP overwrite to identify bad characters that corrupt payload delivery. 6. scripts/06Python3JMPESP.py: overwrites EIP with a hardcoded debugger-derived address intended to redirect execution to ESP, followed by NOPs and INT3 bytes for debugging. 7. scripts/07Python3Shellcode.py: final exploit buffer with EIP overwrite, NOP sled, and embedded Windows x86 shellcode. The documentation states this should be replaced with msfvenom-generated reverse shellcode customized for the operator's LHOST/LPORT. Attack surface and protocol details: - The exploit is purely network-based and targets the FTP service on TCP/21. - The vulnerable input vector is the FTP NOOP command with an overly long argument. - Authentication is performed first using USER anonymous and PASS anonymous, suggesting the exploit path assumes the service accepts or processes commands after this simple login sequence. Notable technical details: - The documented EIP offset is 246 bytes. - Bad characters identified in the walkthrough include at least \x00, \x0a, and \x0d. - The exploit relies on a hardcoded gadget address found during a live debugger session, so reliability outside the demonstrated environment is limited. - The final shellcode stage is operational but not fully generalized; the included payload is embedded directly in the script and the lab instructs the user to regenerate it with msfvenom. Overall assessment: This is a real exploit-development repository rather than a detection script. It demonstrates a classic stack-based buffer overflow against FreeFloat FTP Server 1.0, culminating in arbitrary code execution and a reverse shell in a controlled lab setting. Because the final control-flow redirection uses environment-specific addresses discovered under a debugger, the repository is best classified as an operational PoC rather than a weaponized exploit.
This repository is a small exploit-development lab for a stack-based buffer overflow in FreeFloat FTP Server v1.0 on Windows. It contains 5 files total: 2 Python scripts and 3 Markdown documents. The top-level README only names the CVE, while the substantive content is split between an environment setup guide and a vulnerability-analysis walkthrough. Repository structure and purpose: - `01 Environment/README.md`: setup guide for a Windows exploit-development environment. It references Python 3 for scripting, Immunity Debugger, Python 2.7 for Immunity compatibility, the `mona.py` plugin, VS Code, and IDA Free. It identifies the target binary as `Win32/FTPServer.exe` from `FreeFloatFtpServer1.0.zip`. - `02 Vulnerability/README.md`: explains the target, reverse-engineering context, and fuzzing methodology. It states that unsafe string handling such as `strcpy`/`strcat` is present in the command-processing function and documents that fuzzing the `NOOP` command can crash the service and overwrite EIP with `41414141`. - `02 Vulnerability/Exploit/01Python3Connection.py`: a basic connectivity and protocol-validation script. It opens a TCP socket to `127.0.0.1:21`, receives the FTP banner, sends `USER anonymous`, `PASS anonymous`, and then `NOOP test`, printing server responses. - `02 Vulnerability/Exploit/02Python3Fuzzing.py`: the main proof-of-concept. It repeatedly connects to `127.0.0.1:21`, performs the same login sequence, and sends `NOOP ` followed by an incrementally increasing buffer of `A` bytes. The buffer starts at 100 bytes and grows by 100 bytes per iteration, with a 2-second delay between attempts. Main exploit capabilities: - Network-based interaction with an FTP service over TCP/21. - Anonymous login using hardcoded credentials. - Incremental fuzzing of the `NOOP` command parser. - Triggering a crash/DoS condition in the target service. - Demonstrating attacker control over EIP, indicating a viable path toward a full exploit. This is not a complete weaponized exploit: there is no shellcode, ROP chain, return address selection, bad-character handling in code, or final code-execution stage. The repository is best classified as a proof-of-concept exploit-development aid focused on crash discovery and initial control of execution flow.
This repository is a small educational exploit lab for a classic Windows stack buffer overflow in FreeFloat FTP Server, labeled as CVE-2025-5548. It is not part of a larger exploit framework. The repository contains 10 files total, with 7 Python code files under exploit/ and 3 Markdown documentation files. The code is organized as a step-by-step progression rather than a single polished exploit: initial FTP connectivity test, fuzzing, cyclic-pattern offset discovery, EIP control validation, bad character testing, JMP/CALL ESP redirection, and a final shellcode delivery stage. All exploit scripts use Python sockets to connect to an FTP service at 127.0.0.1:21, authenticate with USER anonymous and PASS anonymous, and then send an oversized NOOP command argument. The vulnerable surface is therefore the FTP NOOP command handler over TCP port 21. The scripts consistently indicate an EIP offset of 246 bytes. Intermediate stages are clearly intended for debugger-assisted exploit development with Immunity Debugger and Mona: one script sends a cyclic pattern, another overwrites EIP with BBBB, another appends a full bytearray to identify bad characters, and another uses a hardcoded debugger-derived gadget address plus NOPs/INT3 bytes to verify control flow reaches ESP. The final script, exploit/07Python3Shellcode.py, is the main exploit stage. It constructs a payload of 246 bytes of padding, a 4-byte little-endian EIP overwrite, a 20-byte NOP sled, and embedded x86 Windows shellcode. The shellcode is hardcoded and not parameterized in the script. The documentation references msfvenom generation of a windows/shell_reverse_tcp payload with LHOST 192.168.1.10 and LPORT 443, but the included Python file itself only embeds raw shellcode bytes and does not expose callback settings in code. Because the return address is hardcoded and described as debugger-session-specific, reliability outside the intended lab environment is limited. The documentation is extensive and explains the exploitation methodology, required tooling, and lab setup. enviroment/readme.md covers installation of Python, Java, VS Code, Nmap, Mona, IDA, Immunity Debugger, Ghidra, Git, and vulnerable binaries. exploit/readme.md documents the exploitation workflow and includes Mona and Metasploit helper commands for pattern creation, offset calculation, bad character analysis, gadget search, and shellcode generation. Overall, the repository’s purpose is educational: to teach manual Windows buffer overflow development against FreeFloat FTP Server, culminating in a working proof-of-concept remote code execution exploit over the FTP control channel.
This repository is a small, research-oriented proof-of-concept for CVE-2025-5548 affecting FreeFloat FTP Server 1.0. It contains 5 files: one Python exploit script and four Markdown documentation files. The main exploit logic is in poc/crash_poc.py, which is the clear entry point. The script accepts a target IP, optional port, and payload size, opens a TCP socket to the FTP service, reads the server banner, and sends an oversized 'NOOP ' command followed by repeated 'A' characters and CRLF. Its purpose is to demonstrate the vulnerable code path and induce service instability or a crash, consistent with a buffer overflow PoC. There is no shellcode, ROP chain, offset calculation, bad character analysis, or post-exploitation logic, so this is a basic crash PoC rather than a weaponized exploit. The documentation in README.md, docs/vulnerability-analysis.md, lab/setup.md, and research/notes.md explains the vulnerability, attack path, lab setup, and future research directions such as determining register control and exact crash offsets. Fingerprintable targets/endpoints are limited to the FTP service over TCP port 21, the NOOP FTP command as the trigger vector, and the example localhost target 127.0.0.1 shown in usage instructions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.