
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25654 is a buffer overflow vulnerability in Core FTP/SFTP Server version 1.2 that allows unauthenticated remote attackers to crash the service by supplying an excessively long string in the User domain field. The vulnerability was formally published to the NVD and GitHub Advisory Database on March 30, 2026, though the underlying exploit dates to 2019. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High), with impact limited to availability (GitHub Advisory, VulnCheck).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), caused by insufficient input length validation in the User domain field of the Core FTP/SFTP Server configuration interface. An attacker can supply a malicious payload of approximately 7,000 bytes into the domain field, triggering a buffer overflow that overwrites adjacent memory and causes the service to crash. No authentication, user interaction, or special privileges are required to trigger the condition, as the vulnerable input can be submitted directly over the network (GitHub Advisory, Exploit-DB).
Successful exploitation results in a complete denial of service for the Core FTP/SFTP Server process, rendering the FTP/SFTP service unavailable to legitimate users. There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue confined to the vulnerable system. Organizations relying on Core FTP/SFTP Server for file transfer operations would experience service disruption until the process is manually restarted or the system is rebooted (GitHub Advisory, VulnCheck).
A proof-of-concept exploit has been publicly available on Exploit-DB (EDB-46371) since 2019, predating the CVE's formal publication (Exploit-DB). The EPSS score is approximately 0.042–0.079%, indicating a low probability of active exploitation in the near term. There is no confirmed evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
'A' * 7000) intended for the domain configuration field.CoreFTPServer.exe or equivalent); absence of the FTP/SFTP service process after it was previously running..dmp) generated in the application directory or Windows error reporting folders following service termination.The vendor has released a patched version; users should update to Core FTP/SFTP Server build 589.42 or later, available from the vendor archive (GitHub Advisory, CoreFTP Archive). As a network-level workaround, administrators should implement firewall rules or network segmentation to restrict access to the FTP/SFTP service to trusted IP ranges only, reducing the attack surface. Additionally, deploying input validation or an application-layer firewall that enforces length restrictions on domain field inputs can help mitigate exploitation risk until patching is complete (VulnCheck).
Coverage of CVE-2019-25654 has been limited to automated vulnerability aggregation platforms and security alert feeds, with no notable vendor statements or prominent researcher commentary identified. Brief mentions appeared on RedPacket Security and InfinitSec following the CVE's formal publication in March 2026, consistent with routine vulnerability disclosure coverage rather than significant community concern (RedPacket Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."