Vulnerability record · CVE-2025-34299 · published 7 November 2025
CVE-2025-34299: Monsta FTP unauthenticated arbitrary file upload leads to RCE
Monstaftp · Monsta Ftp
Monsta FTP versions 2.11 and earlier allow unauthenticated arbitrary file uploads. An attacker can execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server. The flaw is rated critical (CVSS 4.0 score 9.3) and affects a web-based FTP client, making it a serious exposure for internet-facing instances.
Description
Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityUnauthenticated remote code execution with a critical CVSS score and very high EPSS probability, plus a public exploit write-up, makes this an urgent patching priority.
What it is
Monsta FTP versions 2.11 and earlier allow unauthenticated arbitrary file uploads. An attacker can execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server. The flaw is rated critical (CVSS 4.0 score 9.3) and affects a web-based FTP client, making it a serious exposure for internet-facing instances.
Impact
An attacker gains remote code execution on the Monsta FTP host without authentication. This can lead to full compromise of the web server and any data or services it can reach.
Attack surface
The vulnerability is network-reachable (AV:N) with no authentication (PR:N) and no user interaction (UI:N). It is triggered by connecting the Monsta FTP instance to an attacker-controlled (S)FTP server that serves a malicious file.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.72854, 99.4th percentile) and a public exploit write-up exists (WatchTowr reference tagged Exploit). Active exploitation is plausible and should be assumed possible.
What to do
- Upgrade Monsta FTP to a version later than 2.11 as soon as possible.
- Restrict or disable outbound (S)FTP connections from the Monsta FTP host to untrusted servers.
- Place Monsta FTP behind authentication and network access controls; do not expose it directly to the internet.
- Monitor and restrict file upload paths and executable permissions on the web server.
- Apply vendor release notes guidance and review any interim hardening recommendations.
Detection
- Monitor for unexpected file uploads to Monsta FTP directories, especially executable file types.
- Alert on outbound (S)FTP connections from the Monsta FTP host to unknown or external servers.
- Review web server logs for POST requests to Monsta FTP upload endpoints from unauthenticated sessions.
- Check for newly created or modified files in web-accessible directories with executable extensions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://labs.watchtowr.com/whats-that-coming-over-the-hill-monsta-ftp-remote-code-execution-cve-2025-34299/ | ExploitThird Party Advisory |
| https://www.monstaftp.com/notes/ | Release Notes |
| https://www.vulncheck.com/advisories/monsta-ftp-unauthenticated-arbitrary-file-upload | Third Party Advisory |
Track CVE-2025-34299 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-34299), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.