← Back to CVEs
CVE-2018-25254
CRITICAL9.8
Description
NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published4/4/2026
Last Modified4/4/2026
Sourcenvd
Honeypot Sightings0
Weaknesses (CWE)
CWE-787
References
https://en.softonic.com/download/nico-ftp/windows/post-download(disclosure@vulncheck.com)
https://www.exploit-db.com/exploits/45442(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/nico-ftp-buffer-overflow-seh(disclosure@vulncheck.com)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.