CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2018-25254 — NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulner...

Saturday, April 4, 2026 at 02:16 PM UTC·Source: NIST NVD

Updated: Monday, April 6, 2026 at 12:17 AM UTC

Executive Summary

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.

Analysis

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode. CVSS Score: 9.8. Published: 2026-04-04T14:16:21.743.

Indicators of Compromise (2)

CVE (1)
CVE-2018-25254
Source Attribution

Originally published by NIST NVD on Apr 4, 2026. Verified by: NIST.

Related Threats