Critical severityNVD Advisory· Published Jul 15, 2025· Updated Apr 15, 2026
CVE-2025-34110
CVE-2025-34110
Description
A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbitrary files outside the configured FTP root directory. The flaw is due to insufficient sanitation of user-supplied file paths in the FTP GET and PUT command handlers. Exploitation is possible by submitting traversal sequences during FTP operations, enabling access to system-sensitive files. This issue affects only the Windows version of ColoradoFTP.
Patches
116a60c4a74efVulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
4- bitbucket.org/nolife/coloradoftp/commits/16a60c4a74ef477cd8c16ca82442eaab2fbe8c86nvd
- raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/scanner/ftp/colorado_ftp_traversal.rbnvd
- www.exploit-db.com/exploits/40231nvd
- www.vulncheck.com/advisories/colorado-ftp-server-path-traversal-information-disclosurenvd
News mentions
0No linked articles in our index yet.