216.73.216.233

CVE-2010-20122

· Published 21/08/2025 21:15 · Modified 21/08/2025 21:15

Labels: CVE-2010-20122 2025-08-21CVE-2010-20122CWE-121[email protected]

Essential information

Published
21/08/2025 21:15
Modified
21/08/2025 21:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Xftp FTP Client version up to and including 3.0 (build 0238) contain a stack-based buffer overflow vulnerability triggered by a maliciously crafted PWD response from an FTP server. When the client connects to a server and receives an overly long directory string in response to the PWD command, the client fails to properly validate the length of the input before copying it into a fixed-size buffer. This results in memory corruption and allows remote attackers to execute arbitrary code on the client system.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
netdisk / xftp cpe:2.3:a:netdisk:xftp:*:*:*:*:*:*:*:*

References