216.73.216.233

CVE-2025-34110

· Published 15/07/2025 13:15 · Modified 15/07/2025 20:07

Labels: CVE-2025-34110 2025-07-15CVE-2025-34110CWE-22[email protected]

Essential information

Published
15/07/2025 13:15
Modified
15/07/2025 20:07
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbitrary files outside the configured FTP root directory. The flaw is due to insufficient sanitation of user-supplied file paths in the FTP GET and PUT command handlers. Exploitation is possible by submitting traversal sequences during FTP operations, enabling access to system-sensitive files. This issue affects only the Windows version of ColoradoFTP.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
coloradoftp / server cpe:2.3:a:coloradoftp:server:1.3-build8:*:*:*:*:*:*:*

References