CVE-2018-25254 PUBLISHED

NICO-FTP 3.0.1.19 Buffer Overflow SEH

Assigner: VulnCheck
Reserved: 04.04.2026 Published: 04.04.2026 Updated: 04.04.2026

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor nico-ftp
Product NICO-FTP
Versions
  • Version 3.0.1.19 is affected

Credits

  • Abdullah Alıç finder

References

Problem Types

  • Out-of-bounds Write CWE