CVE-2019-25654
CoreFTP Server vulnerability analysis and mitigation

Overview

CVE-2019-25654 is a buffer overflow vulnerability in Core FTP/SFTP Server version 1.2 that allows unauthenticated remote attackers to crash the service by supplying an excessively long string in the User domain field. The vulnerability was formally published to the NVD and GitHub Advisory Database on March 30, 2026, though the underlying exploit dates to 2019. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High), with impact limited to availability (GitHub Advisory, VulnCheck).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write), caused by insufficient input length validation in the User domain field of the Core FTP/SFTP Server configuration interface. An attacker can supply a malicious payload of approximately 7,000 bytes into the domain field, triggering a buffer overflow that overwrites adjacent memory and causes the service to crash. No authentication, user interaction, or special privileges are required to trigger the condition, as the vulnerable input can be submitted directly over the network (GitHub Advisory, Exploit-DB).

Impact

Successful exploitation results in a complete denial of service for the Core FTP/SFTP Server process, rendering the FTP/SFTP service unavailable to legitimate users. There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue confined to the vulnerable system. Organizations relying on Core FTP/SFTP Server for file transfer operations would experience service disruption until the process is manually restarted or the system is rebooted (GitHub Advisory, VulnCheck).

Exploitability

A proof-of-concept exploit has been publicly available on Exploit-DB (EDB-46371) since 2019, predating the CVE's formal publication (Exploit-DB). The EPSS score is approximately 0.042–0.079%, indicating a low probability of active exploitation in the near term. There is no confirmed evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible hosts running Core FTP/SFTP Server version 1.2 using port scanning tools (e.g., Nmap targeting default FTP port 21 or SFTP port 22) or banner grabbing to confirm the software version.
  2. Obtain PoC: Retrieve the publicly available exploit from Exploit-DB (EDB-46371), which contains a pre-built payload targeting the User domain field.
  3. Craft payload: Construct a malicious input string of approximately 7,000 bytes (e.g., a repeated character sequence such as 'A' * 7000) intended for the domain configuration field.
  4. Submit payload: Connect to the Core FTP/SFTP Server and supply the oversized string in the User domain field during configuration or authentication interaction, triggering the out-of-bounds write.
  5. Achieve DoS: The server process crashes due to memory corruption, resulting in a complete denial of service for all FTP/SFTP clients until the service is manually restarted (Exploit-DB, GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated connection attempts to FTP (port 21) or SFTP (port 22) from a single external IP address; network traffic containing abnormally large payloads (≥7,000 bytes) in the domain field of FTP/SFTP handshake or configuration requests.
  • Logs: Core FTP/SFTP Server logs showing abrupt service termination or crash events; Windows Event Log entries (Event ID 1000 or similar application crash events) referencing the Core FTP/SFTP Server process.
  • Process: Unexpected termination of the Core FTP/SFTP Server process (CoreFTPServer.exe or equivalent); absence of the FTP/SFTP service process after it was previously running.
  • File System: Crash dump files (.dmp) generated in the application directory or Windows error reporting folders following service termination.

Mitigation and workarounds

The vendor has released a patched version; users should update to Core FTP/SFTP Server build 589.42 or later, available from the vendor archive (GitHub Advisory, CoreFTP Archive). As a network-level workaround, administrators should implement firewall rules or network segmentation to restrict access to the FTP/SFTP service to trusted IP ranges only, reducing the attack surface. Additionally, deploying input validation or an application-layer firewall that enforces length restrictions on domain field inputs can help mitigate exploitation risk until patching is complete (VulnCheck).

Community reactions

Coverage of CVE-2019-25654 has been limited to automated vulnerability aggregation platforms and security alert feeds, with no notable vendor statements or prominent researcher commentary identified. Brief mentions appeared on RedPacket Security and InfinitSec following the CVE's formal publication in March 2026, consistent with routine vulnerability disclosure coverage rather than significant community concern (RedPacket Security).

Additional resources


SourceThis report was generated using AI

Related CoreFTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-19596CRITICAL9.8
  • CoreFTP Server logoCoreFTP Server
  • cpe:2.3:a:coreftp:core_ftp
NoNoApr 05, 2021
CVE-2019-25686HIGH8.7
  • CoreFTP Server logoCoreFTP Server
  • cpe:2.3:a:coreftp:core_ftp
NoYesApr 05, 2026
CVE-2019-25654HIGH8.7
  • CoreFTP Server logoCoreFTP Server
  • cpe:2.3:a:coreftp:core_ftp
NoNoMar 30, 2026
CVE-2022-22836MEDIUM6.5
  • CoreFTP Server logoCoreFTP Server
  • cpe:2.3:a:coreftp:core_ftp
NoYesJan 10, 2022
CVE-2022-22899MEDIUM5.5
  • CoreFTP Server logoCoreFTP Server
  • cpe:2.3:a:coreftp:core_ftp
NoYesFeb 17, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management