CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2018-25254 — NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulner...
Saturday, April 4, 2026 at 02:16 PM UTC·Source: NIST NVD
Updated: Monday, April 6, 2026 at 12:17 AM UTC
Executive Summary
NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.
Analysis
NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.
CVSS Score: 9.8. Published: 2026-04-04T14:16:21.743.