CVE-2019-25614Disclosure(freefloat / freefloat_ftp_server)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch freefloat freefloat_ftp_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freefloat_ftp_server

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-22); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
freefloat_ftp_server

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-22: 2Mentions · 2026-03-23: 2PoC Mentioned / Linked · 2026-03-22: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-22: 2Technical Details · 2026-03-23: 203-2203-23
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Full discourse4 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2019-25614: CRITICAL] Buffer overflow vulnerability in Free Float FTP 1.0 STOR command handler allows remote attackers to execute arbitrary code via crafted STOR request with oversized payload.#cve,CVE-2019-25614,#cybersecurity https://cvefind.com/CVE-2019-25614

    Post summary

    The post alerts about a critical buffer overflow in Free Float FTP 1.0 that enables remote code execution through a crafted STOR command with an oversized payload.

    00011139
    605 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2019-25614 Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted ST… https://www.cve.org/CVERecord?id=CVE-2019-25614

    Post summary

    The note is a straightforward CVE disclosure, describing a buffer overflow in Free Float FTP 1.0’s STOR command that could lead to arbitrary code execution.

    00000104
    56.8K followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    Design Flaw Spotlight: Free Float FTP STOR buffer overflow enables internal reach Affected: FreeFloat/Free Float FTP 1.0 Internet-facing risks dominate, led by FTP service vulnerabilities with high exploitability. • CVE-2019-25614 (CVSS 9.8) Remote attackers can execute arbitrary code on Free Float FTP 1.0 by sending a crafted STOR request with 247 bytes of padding followed by a return address and shellcode after anonymous authentication. 🛠️ Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (process spawning, webshell/file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces a critical CVE‑2019‑25614 buffer overflow in FreeFloat FTP 1.0, details the exploit vector and impact, and urges patching or mitigation steps.

    0000052
    96 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2019-25614: Free Float FTP 1.0 S... Anonymous FTP + 247-byte STOR overflow = instant RCE on legacy servers still running this ancient trash. #BufferOverflow #FTP #RCE. https://zerodaysignal.com/vulnerability/CVE-2019-25614 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses CVE-2019-25614, a buffer overflow in Free Float FTP 1.0 that allows remote code execution via an anonymous FTP STOR command, with a 247‑byte payload.

    0000055
    158 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreefloatfreefloat_ftp_server1.0--

Explore more