CVE-2018-25254Disclosure(nico-ftp_project / nico-ftp)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for nico-ftp_project nico-ftp systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nico-ftp

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-04); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
nico-ftp

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-04: 3Mentions · 2026-04-05: 1PoC Mentioned / Linked · 2026-04-04: 1Exploit Tool / Code · 2026-04-04: 1Technical Details · 2026-04-04: 3Technical Details · 2026-04-05: 104-0404-05
Signal classification3 categories
Disclosure
250.0%
Exploit
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-043
Disclosure2Exploit1
2026-04-051
General1
Full discourse4 posts
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2016-20052 | CVSS 9.8 🔴 CVE-2018-25254 | CVSS 9.8 🟠 CVE-2026-3666 | CVSS 8.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists top CVEs with CVSS scores and a link to a vulnerabilities page, but provides no PoC, exploit, patch, or active exploitation information.

    0000036
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2018-25254 NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP … https://www.cve.org/CVERecord?id=CVE-2018-25254

    Post summary

    The post announces a buffer‑overflow RCE vulnerability in NICO‑FTP 3.0.1.19, providing technical details but no exploit or mitigation information.

    00000121
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2018-25254: CRITICAL] NICO-FTP 3.0.1.19 has a critical vulnerability enabling remote attackers to execute arbitrary code through crafted FTP commands, posing severe cyber security risks.#cve,CVE-2018-25254,#cybersecurity https://cvefind.com/CVE-2018-25254

    Post summary

    The tweet announces that CVE‑2018‑25254 is a remote code execution vulnerability in NICO‑FTP 3.0.1.19, with no PoC, exploit, or patch referenced.

    0000061
    619 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2018-25254: NICO-FTP 3.0.1.19 Buffer Overflo... SEH overflow with public exploit makes this ancient FTP server a drive-by RCE goldmine for anyone still running legacy ... https://zerodaysignal.com/vulnerability/CVE-2018-25254 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces that CVE‑2018‑25254 in NICO‑FTP is a SEH‑based buffer overflow with a publicly available exploit, enabling drive‑by remote code execution for legacy installations.

    0000062
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnico-ftp_projectnico-ftp---

Explore more