CVE-2026-67193
Xlight FTP Server < 3.9.5 Information Disclosure via USER Command
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command with a username ending in the :adm suffix. Attackers can trigger the admin protocol path within the standard FTP listener pre-authentication to leak timing information from the FTP 331 response without requiring a separate port or configuration change.
| CWE | CWE-203 |
| Vendor | xlight |
| Product | xlight ftp server |
| Published | Jul 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for xlight xlight ftp server
Be the first to know when new medium vulnerabilities affecting xlight xlight ftp server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
Xlight / Xlight FTP Server
0 < 3.9.5
References
Credits
McCaulay Hudson (@_McCaulay) of watchTowr