CVE-2018-25254
NICO-FTP 3.0.1.19 Buffer Overflow SEH
CVSS Score
9.8
EPSS Score
0.2%
EPSS Percentile
39th
NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.
| CWE | CWE-787 |
| Vendor | nico-ftp |
| Product | nico-ftp |
| Published | Apr 4, 2026 |
| Last Updated | Apr 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for nico-ftp nico-ftp
Be the first to know when new critical vulnerabilities affecting nico-ftp nico-ftp are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
nico-ftp / NICO-FTP
3.0.1.19
References
Credits
Abdullah AlΔ±Γ§