Critical severityOSV Advisory· Published Jul 15, 2025· Updated Apr 15, 2026
CVE-2025-34110
CVE-2025-34110
Description
A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbitrary files outside the configured FTP root directory. The flaw is due to insufficient sanitation of user-supplied file paths in the FTP GET and PUT command handlers. Exploitation is possible by submitting traversal sequences during FTP operations, enabling access to system-sensitive files. This issue affects only the Windows version of ColoradoFTP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 1.3
- Range: <=1.3 Build 8
Patches
Vulnerability mechanics
References
4- bitbucket.org/nolife/coloradoftp/commits/16a60c4a74ef477cd8c16ca82442eaab2fbe8c86nvd
- raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/scanner/ftp/colorado_ftp_traversal.rbnvd
- www.exploit-db.com/exploits/40231nvd
- www.vulncheck.com/advisories/colorado-ftp-server-path-traversal-information-disclosurenvd
News mentions
0No linked articles in our index yet.