
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25681 is a Structured Exception Handler (SEH) overwrite vulnerability in Xlight FTP Server version 3.9.1 that allows local attackers to crash the application and potentially execute arbitrary code. The vulnerability is triggered by injecting a crafted 428-byte payload through the program execution field in the virtual server configuration, causing a buffer overflow that corrupts the SEH chain. It was formally published to the CVE database on April 5, 2026, and carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory, Feedly).
The root cause is an out-of-bounds write (CWE-787) in Xlight FTP Server 3.9.1's handling of input in the virtual server configuration's program execution field. By supplying a crafted buffer string of approximately 428 bytes, an attacker can overflow the buffer, overwrite SEH (Structured Exception Handler) pointers, and corrupt the SEH chain — a classic Windows exploitation technique that hijacks exception dispatch to redirect execution flow. Exploitation requires local access to the FTP server's administrative configuration interface, and no special privileges are required under the CVSS v4.0 assessment. A public exploit entry exists on Exploit-DB (EDB-46458) (GitHub Advisory, Exploit-DB).
Successful exploitation can result in a full compromise of the affected system's confidentiality, integrity, and availability. A local attacker can crash the Xlight FTP Server application and, by controlling the overwritten SEH pointer, potentially achieve arbitrary code execution in the context of the FTP server process. This could enable unauthorized access to sensitive data managed by the FTP server, modification of server configurations, or use of the compromised host as a pivot point for further lateral movement within the network (GitHub Advisory, Feedly).
A public exploit reference exists on Exploit-DB (EDB-46458), though Feedly's analysis notes the exploit resource lacked sufficient context to confirm it is a fully weaponized, functional exploit (Exploit-DB). There is no confirmed evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.013–0.019%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
xlightftpd.exe) around the time of configuration changes.cmd.exe, powershell.exe, or network utilities like nc.exe) that are not part of normal FTP server operation.Upgrade Xlight FTP Server beyond version 3.9.1 to a patched release as referenced in the GitHub Advisory (GitHub Advisory). As an immediate workaround, restrict local access to the Xlight FTP Server administrative configuration interface to only authorized administrators, applying the principle of least privilege. Monitor for suspicious configuration changes and unexpected application crashes that may indicate exploitation attempts. Consult the VulnCheck advisory and the official Xlight FTP Server site for the latest patched binaries (VulnCheck Advisory, Xlight FTP Site).
A brief mention of the vulnerability was noted on Bluesky social media shortly after publication in April 2026, and a technical write-up was published at infinitsec.net covering the SEH overwrite mechanics (infinitsec.net). No major vendor statements or significant mainstream security media coverage has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."