← Vulnerability feed

Vulnerability record · CVE-2019-25686 · published 5 April 2026

CVE-2019-25686: Coreftp core ftp missing authentication for critical function vulnerability

CCoreftp · Core Ftp

Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violation and crash the FTP server process.

8.7 CVSS 4.0 High EPSS 0.47% · top 62.2% CWE-306 · Missing authentication for critical function
8.7CVSS 4.0 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
24 Jul 2026Last modified by NVD

Description

Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violation and crash the FTP server process.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-25686 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-19596Coreftp core ftp classic buffer overflow vulnerabilityBuffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.EPSS 1.3%9.8CVE-2018-12113Coreftp core ftp memory buffer overflow vulnerabilityCore FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.EPSS 6.9%9.3CVE-2013-3930Coreftp core ftp memory buffer overflow vulnerabilityStack-based buffer overflow in Core FTP before 2.2 build 1785 allows remote FTP servers to execute arbitrary code via a crafted directory name in a C…EPSS 3.0%9.3CVE-2009-3484Coreftp core ftp memory buffer overflow vulnerabilityStack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP …EPSS 5.6%8.7CVE-2019-25654Coreftp core ftp out-of-bounds write vulnerabilityCore FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string …EPSS 0.69%7.8CVE-2014-1215Coreftp core ftp memory buffer overflow vulnerabilityMultiple buffer overflows in Core FTP Server before 1.2 build 508 allow local users to gain privileges via vectors related to reading data from confi…EPSS 0.36%7.5CVE-2020-19595Coreftp core ftp classic buffer overflow vulnerabilityBuffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.EPSS 1.1%7.5CVE-2018-20658Coreftp core ftp improper input validation vulnerabilityThe server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD comma…EPSS 8.5%

Source: NIST National Vulnerability Database (record CVE-2019-25686), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.