CVE-2019-25681
Xlight FTP Server vulnerability analysis and mitigation

Overview

CVE-2019-25681 is a Structured Exception Handler (SEH) overwrite vulnerability in Xlight FTP Server version 3.9.1 that allows local attackers to crash the application and potentially execute arbitrary code. The vulnerability is triggered by injecting a crafted 428-byte payload through the program execution field in the virtual server configuration, causing a buffer overflow that corrupts the SEH chain. It was formally published to the CVE database on April 5, 2026, and carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is an out-of-bounds write (CWE-787) in Xlight FTP Server 3.9.1's handling of input in the virtual server configuration's program execution field. By supplying a crafted buffer string of approximately 428 bytes, an attacker can overflow the buffer, overwrite SEH (Structured Exception Handler) pointers, and corrupt the SEH chain — a classic Windows exploitation technique that hijacks exception dispatch to redirect execution flow. Exploitation requires local access to the FTP server's administrative configuration interface, and no special privileges are required under the CVSS v4.0 assessment. A public exploit entry exists on Exploit-DB (EDB-46458) (GitHub Advisory, Exploit-DB).

Impact

Successful exploitation can result in a full compromise of the affected system's confidentiality, integrity, and availability. A local attacker can crash the Xlight FTP Server application and, by controlling the overwritten SEH pointer, potentially achieve arbitrary code execution in the context of the FTP server process. This could enable unauthorized access to sensitive data managed by the FTP server, modification of server configurations, or use of the compromised host as a pivot point for further lateral movement within the network (GitHub Advisory, Feedly).

Exploitability

A public exploit reference exists on Exploit-DB (EDB-46458), though Feedly's analysis notes the exploit resource lacked sufficient context to confirm it is a fully weaponized, functional exploit (Exploit-DB). There is no confirmed evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.013–0.019%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Gain Local Access: Obtain local access to the system running Xlight FTP Server 3.9.1, either through a valid user account or by leveraging another vulnerability to gain a foothold on the host.
  2. Access Virtual Server Configuration: Open the Xlight FTP Server administrative interface and navigate to the virtual server configuration panel.
  3. Locate Program Execution Field: Identify the "program execution" input field within the virtual server settings, which is the vulnerable input vector.
  4. Craft Malicious Payload: Construct a 428-byte buffer overflow payload designed to overwrite the SEH (Structured Exception Handler) chain pointers. This typically involves a pattern of junk bytes, a POP/POP/RET gadget address to control exception handler execution, and shellcode.
  5. Inject Payload: Enter the crafted buffer string into the program execution field and save or apply the configuration to trigger the buffer overflow.
  6. Trigger Exception: Cause the application to process the malicious input, triggering an exception that invokes the corrupted SEH chain.
  7. Achieve Code Execution: The overwritten SEH pointer redirects execution to the attacker-controlled shellcode, enabling arbitrary command execution on the host (Exploit-DB, GitHub Advisory).

Indicators of compromise

  • Logs: Unexpected application crash logs or Windows Event Log entries (Event ID 1000/1001) referencing the Xlight FTP Server process (xlightftpd.exe) around the time of configuration changes.
  • Process: Unusual child processes spawned by the Xlight FTP Server process (e.g., cmd.exe, powershell.exe, or network utilities like nc.exe) that are not part of normal FTP server operation.
  • File System: Unexpected files written to the Xlight FTP Server installation directory or temp directories, particularly executables or scripts created around the time of a crash event.
  • Configuration: Unauthorized or unexpected changes to the virtual server configuration, particularly in the program execution field, containing long or non-standard strings.

Mitigation and workarounds

Upgrade Xlight FTP Server beyond version 3.9.1 to a patched release as referenced in the GitHub Advisory (GitHub Advisory). As an immediate workaround, restrict local access to the Xlight FTP Server administrative configuration interface to only authorized administrators, applying the principle of least privilege. Monitor for suspicious configuration changes and unexpected application crashes that may indicate exploitation attempts. Consult the VulnCheck advisory and the official Xlight FTP Server site for the latest patched binaries (VulnCheck Advisory, Xlight FTP Site).

Community reactions

A brief mention of the vulnerability was noted on Bluesky social media shortly after publication in April 2026, and a technical write-up was published at infinitsec.net covering the SEH overwrite mechanics (infinitsec.net). No major vendor statements or significant mainstream security media coverage has been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related Xlight FTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-67191CRITICAL9.3
  • Xlight FTP Server logoXlight FTP Server
  • cpe:2.3:a:xlightftpd:xlight_ftp_server
NoYesJul 29, 2026
CVE-2026-67192CRITICAL9.2
  • Xlight FTP Server logoXlight FTP Server
  • cpe:2.3:a:xlightftpd:xlight_ftp_server
NoYesJul 29, 2026
CVE-2019-25681HIGH8.6
  • Xlight FTP Server logoXlight FTP Server
  • cpe:2.3:a:xlightftpd:xlight_ftp_server
NoNoApr 05, 2026
CVE-2026-67193MEDIUM6.9
  • Xlight FTP Server logoXlight FTP Server
  • cpe:2.3:a:xlightftpd:xlight_ftp_server
NoYesJul 29, 2026
CVE-2023-53886MEDIUM5.1
  • Xlight FTP Server logoXlight FTP Server
  • cpe:2.3:a:xlightftpd:xlight_ftp_server
NoNoDec 15, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management