πŸ” CVE Alert

CVE-2018-25254

CRITICAL 9.8

NICO-FTP 3.0.1.19 Buffer Overflow SEH

CVSS Score
9.8
EPSS Score
0.2%
EPSS Percentile
39th

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.

CWE CWE-787
Vendor nico-ftp
Product nico-ftp
Published Apr 4, 2026
Last Updated Apr 6, 2026
Stay Ahead of the Next One

Get instant alerts for nico-ftp nico-ftp

Be the first to know when new critical vulnerabilities affecting nico-ftp nico-ftp are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

nico-ftp / NICO-FTP
3.0.1.19

References

NVD β†— CVE.org β†— EPSS Data β†—
exploit-db.com: https://www.exploit-db.com/exploits/45442 en.softonic.com: https://en.softonic.com/download/nico-ftp/windows/post-download vulncheck.com: https://www.vulncheck.com/advisories/nico-ftp-buffer-overflow-seh

Credits

Abdullah AlΔ±Γ§