Critical severity9.8NVD Advisory· Published Nov 7, 2025· Updated Jun 17, 2026
CVE-2025-34299
CVE-2025-34299
Description
Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=2.11
- Monsta Limited of New Zealand/Monsta FTPv5Range: 0
Patches
Vulnerability mechanics
References
3- labs.watchtowr.com/whats-that-coming-over-the-hill-monsta-ftp-remote-code-execution-cve-2025-34299/nvdExploitThird Party Advisory
- www.vulncheck.com/advisories/monsta-ftp-unauthenticated-arbitrary-file-uploadnvdThird Party Advisory
- www.monstaftp.com/notes/nvdRelease Notes
News mentions
0No linked articles in our index yet.