cvedb.io
CVE-2018-25254
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2026-04-04T14:16:21.743 · Last modified 2026-07-24T22:10:00.140

Summary

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.

Affected products

nico-ftp_project — nico-ftp

Does this affect you?

Add your gear to cvedb and we'll alert you only when nico-ftp_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.