CVE-2018-25254

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nico-ftp_project:nico-ftp:*:*:*:*:*:*:*:*

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) NICO-FTP 3.0.1.19 contiene una vulnerabilidad de desbordamiento de búfer en el gestor de excepciones estructuradas que permite a atacantes remotos ejecutar código arbitrario mediante el envío de comandos FTP manipulados. Los atacantes pueden conectarse al servicio FTP y enviar datos de tamaño excesivo en los gestores de respuesta para sobrescribir los punteros SEH y redirigir la ejecución al shellcode inyectado.

27 Apr 2026, 13:26

Type Values Removed Values Added
First Time Nico-ftp Project nico-ftp
Nico-ftp Project
References () https://en.softonic.com/download/nico-ftp/windows/post-download - () https://en.softonic.com/download/nico-ftp/windows/post-download - Product
References () https://www.exploit-db.com/exploits/45442 - () https://www.exploit-db.com/exploits/45442 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/nico-ftp-buffer-overflow-seh - () https://www.vulncheck.com/advisories/nico-ftp-buffer-overflow-seh - Third Party Advisory
CPE cpe:2.3:a:nico-ftp_project:nico-ftp:*:*:*:*:*:*:*:*

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-07-24 22:10


NVD link : CVE-2018-25254

Mitre link : CVE-2018-25254

CVE.ORG link : CVE-2018-25254


JSON object : View

Products Affected

nico-ftp_project

  • nico-ftp
CWE
CWE-787

Out-of-bounds Write