๐Ÿ” CVE Alert

CVE-2025-34107

UNKNOWN 0.0

WinaXe 7.7 FTP Client Remote Buffer Overflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A buffer overflow vulnerability exists in the WinaXe FTP Client version 7.7 within the FTP banner parsing functionality, WCMDPA10.dll. When the client connects to a remote FTP server and receives an overly long '220 Server Ready' response, the vulnerable component responsible for parsing the banner overflows a stack buffer, leading to arbitrary code execution under the context of the user.

CWE CWE-121
Vendor labf
Product winaxe ftp client
Published Jul 15, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for labf winaxe ftp client

Be the first to know when new unknown vulnerabilities affecting labf winaxe ftp client are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

LabF / WinaXe FTP Client
7.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/ftp/winaxe_server_ready.rb hyp3rlinx.altervista.org: http://hyp3rlinx.altervista.org/advisories/WINAXE-FTP-CLIENT-REMOTE-BUFFER-OVERFLOW.txt exploit-db.com: https://www.exploit-db.com/exploits/40767 vulncheck.com: https://www.vulncheck.com/advisories/wina-xe-ftp-client-remote-buffer-overflow

Credits

hyp3rlinx