CVE-2018-25366

CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut is created and launched.
Configurations

No configuration.

History

23 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) CuteFTP 5.0 XP contiene una vulnerabilidad de desbordamiento de búfer que permite a atacantes locales ejecutar código arbitrario inyectando una carga útil maliciosa en el campo de etiqueta del Administrador de Sitios. Los atacantes pueden crear una carga útil que exceda los 520 bytes que sobrescribe la dirección de retorno y ejecuta shellcode cuando se crea y se lanza un acceso directo.

25 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-25 15:16

Updated : 2026-07-23 19:10


NVD link : CVE-2018-25366

Mitre link : CVE-2018-25366

CVE.ORG link : CVE-2018-25366


JSON object : View

Products Affected

No product.

CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')