CVE-2019-25683
FileZilla FTP Client vulnerability analysis and mitigation

Overview

CVE-2019-25683 is a denial of service (DoS) vulnerability in FileZilla Client 3.40.0 affecting the application's local search functionality. A local attacker can crash the application by supplying a malformed path string in the search directory field. The vulnerability was formally published to the NVD and GitHub Advisory Database on April 5, 2026, and assigned a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory).

Technical details

The vulnerability is classified under CWE-532 (Insertion of Sensitive Information into Log File) by the GitHub Advisory Database, though Feedly's estimate also associates it with CWE-125 (Out-of-bounds Read), suggesting the crash may involve improper memory access when processing an oversized or malformed path string (GitHub Advisory). Exploitation requires a local attacker to enter a crafted path string — specifically 384 'A' characters followed by 'BBBB' and 'CCCC' sequences — into the search directory field and initiate a local search operation. A public proof-of-concept Python script on Exploit-DB automates generation of this malicious payload by writing the crafted string to a file (Exploit-DB). No network access or elevated privileges are required to trigger the crash.

Impact

Successful exploitation causes the FileZilla Client application to crash, resulting in a complete loss of availability for the affected application instance. There is no impact on confidentiality or integrity, and the vulnerability is scoped to the vulnerable system only with no lateral movement potential. The impact is limited to disruption of the FTP client session for the affected local user (GitHub Advisory).

Exploitation steps

  1. Prepare the payload: Run the public Python PoC script from Exploit-DB, which generates a file (buff.txt) containing a crafted path: a forward slash followed by 384 'A' characters, then 'BBBB', then 'CCCC' (e.g., /AAAA...AAAABBBBCCCC).
  2. Access FileZilla Client: Open FileZilla Client version 3.40.0 on the target system with local user access.
  3. Navigate to local search: Open the local file search functionality within the FileZilla Client interface.
  4. Enter the malformed path: Copy the crafted path string from buff.txt and paste it into the search directory field.
  5. Initiate the search: Start the local search operation, which triggers the application crash and achieves denial of service (Exploit-DB).

Indicators of compromise

  • Process: Unexpected termination of the filezilla.exe (Windows) or filezilla (Linux) process without user-initiated close action.
  • Logs: Application crash logs or Windows Event Viewer entries (Event ID 1000/1001) referencing FileZilla Client crashing, potentially with a faulting module related to path handling.
  • File System: Presence of a file named buff.txt or similar containing a string of 384+ repeated characters followed by 'BBBB' and 'CCCC' in user-accessible directories, indicative of PoC payload generation (Exploit-DB).

Mitigation and workarounds

Users should upgrade FileZilla Client to a version beyond 3.40.0, as the vulnerability is specific to that release. A patch is referenced via GitHub Advisory GHSA-g5wj-4965-6q9m, though specific patched version numbers are not explicitly listed in available advisories (GitHub Advisory). As a temporary workaround, administrators can restrict local user access to FileZilla Client or advise users to avoid using the local search functionality until an upgrade is applied.

Additional resources


SourceThis report was generated using AI

Related FileZilla FTP Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-53959HIGH8.5
  • FileZilla FTP Client logoFileZilla FTP Client
  • cpe:2.3:a:filezilla-project:filezilla_client
NoYesDec 19, 2025
CVE-2016-15003HIGH7.8
  • FileZilla FTP Client logoFileZilla FTP Client
  • cpe:2.3:a:filezilla-project:filezilla_client
NoYesJul 18, 2022
CVE-2019-25683MEDIUM6.9
  • FileZilla FTP Client logoFileZilla FTP Client
  • filezilla
NoNoApr 05, 2026
CVE-2024-31497MEDIUM5.9
  • NixOS logoNixOS
  • libfilezilla-debuginfo
NoYesApr 15, 2024
CVE-2023-48795MEDIUM5.9
  • MySQL logoMySQL
  • erlang-wx-src
NoYesDec 18, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management