← Vulnerability feed

Vulnerability record · CVE-2019-25654 · published 30 March 2026

CVE-2019-25654: Coreftp core ftp out-of-bounds write vulnerability

CCoreftp · Core Ftp

Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an application crash and deny service.

8.7 CVSS 4.0 High EPSS 0.69% · top 49.1% CWE-787 · Out-of-bounds write
8.7CVSS 4.0 base score
0.69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an application crash and deny service.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-25654 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-19596Coreftp core ftp classic buffer overflow vulnerabilityBuffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.EPSS 1.3%9.8CVE-2018-12113Coreftp core ftp memory buffer overflow vulnerabilityCore FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.EPSS 6.9%9.3CVE-2013-3930Coreftp core ftp memory buffer overflow vulnerabilityStack-based buffer overflow in Core FTP before 2.2 build 1785 allows remote FTP servers to execute arbitrary code via a crafted directory name in a C…EPSS 3.0%9.3CVE-2009-3484Coreftp core ftp memory buffer overflow vulnerabilityStack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP …EPSS 5.6%8.7CVE-2019-25686Coreftp core ftp missing authentication for critical function vulnerabilityCore FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by s…EPSS 0.47%7.8CVE-2014-1215Coreftp core ftp memory buffer overflow vulnerabilityMultiple buffer overflows in Core FTP Server before 1.2 build 508 allow local users to gain privileges via vectors related to reading data from confi…EPSS 0.36%7.5CVE-2020-19595Coreftp core ftp classic buffer overflow vulnerabilityBuffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.EPSS 1.1%7.5CVE-2018-20658Coreftp core ftp improper input validation vulnerabilityThe server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD comma…EPSS 8.5%

Source: NIST National Vulnerability Database (record CVE-2019-25654), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.