VulnerabilityAnalyzed
CVE-2025-5548
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0.
MEDIUM 6.9EPSS 15.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component NOOP Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 14.99% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-120
- Affected
- freefloat/freefloat ftp server
- Source
- cna@vuldb.com
References
- https://fitoxs.com/exploit/exploit-181bb9e57fbeedb99be8435f014d23b3d936df3ff95db127e57d6832dc48df8f.txtExploit
- https://vuldb.com/?ctiid.310998Permissions Required, VDB Entry
- https://vuldb.com/?id.310998Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.586982Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.