MEDIUM Severity

CVE-2025-5330

Critical vulnerability in FreeFloat FTP Server 1.0 leading to buffer overflow

Overview

The RETR Command Handler component of FreeFloat FTP Server 1.0 has been identified with a critical vulnerability that causes buffer overflow. The exploit has been publicly disclosed and is open to remote attacks.

Technical Details

An unknown part of the RETR Command Handler component in FreeFloat FTP Server 1.0 was manipulated, thus leading to a buffer overflow vulnerability. This susceptibility allows attackers to remotely run the exploit.

CVSS Metrics

  • Base Score: 7.3
  • Attack Vector: NETWORK
  • Attack Complexity: LOW
  • Privileges Required: NONE
  • User Interaction: NONE
  • Confidentiality Impact: LOW
  • Integrity Impact: LOW
  • Availability Impact: LOW

Impact

The vulnerability could potentially allow an attacker to compromise the FreeFloat FTP Server and lead to data corruption or loss.

Recommendations

Users are advised to immediately apply necessary patches or update to the latest version of the FreeFloat FTP Server as soon as possible. Pay close attention to access control and proper user privilege configuration to avoid granting unnecessary rights to users.

Threat Metrics

  • "cvss_score": 7.3
  • "severity": "MEDIUM"
  • "attack_vector": "NETWORK"
  • "attack_complexity": "LOW"

CWE-119, CWE-120