Critical severity9.8NVD Advisory· Published Mar 22, 2026· Updated Jun 17, 2026
CVE-2019-25614
CVE-2019-25614
Description
Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:freefloat:freefloat_ftp_server:1.0:*:*:*:*:*:*:*
- Range: <=1.0
- Freefloat/Free Float FTPv5Range: 1.0
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/46763nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/free-float-ftp-stor-command-remote-buffer-overflownvdThird Party Advisory
- www.freefloat.com/software/freefloatftpserver.zipnvdBroken Link
News mentions
0No linked articles in our index yet.