CVE-2018-25254 CRITICAL

CVE-2018-25254: NICO-FTP 3.0.1.19 Buffer Overflow SEH

Vendor Nico-Ftp
Product NICO-FTP
Weakness CWE-787
Published April 4, 2026
Last update April 6, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.

Key dates

02Disclosure timeline

April 4, 2026 CVE published
April 6, 2026 Record updated