
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53886 is a stack-based buffer overflow vulnerability in Xlight FTP Server version 3.9.3.6, specifically within the 'Execute Program' configuration feature. Attackers can trigger the flaw by inserting a string of 294 or more characters into the program execution configuration field, causing the application to crash and resulting in a denial of service condition. The vulnerability was assigned by VulnCheck and published on December 15, 2025, with NVD initial analysis completed on December 18, 2025. It carries a CVSS v3.1 base score of 7.5 (High) per NIST NVD, and a CVSS v4.0 base score of 5.1 (Medium) per the CNA (VulnCheck) (VulnCheck Advisory, Exploit-DB).
The root cause is a stack-based buffer overflow (CWE-121) combined with an out-of-bounds write (CWE-787) in the 'Execute Program' configuration handler of Xlight FTP Server 3.9.3.6. The application fails to properly validate the length of user-supplied input in the program execution configuration field; when an attacker supplies 294 or more characters, the input overflows a fixed-size stack buffer, corrupting adjacent stack memory and crashing the process. Based on the CVSS v3.1 vector (AV:N/AC:L/PR:N/UI:N), the vulnerability is network-accessible with low complexity and requires no authentication or user interaction, though the CVSS v4.0 CNA assessment (AV:L/PR:L/UI:A) suggests the configuration field may require local or authenticated access to set. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB, VulnCheck Advisory).
Successful exploitation results in a crash of the Xlight FTP Server process, causing a denial of service that disrupts all file transfer operations hosted by the server. There is no evidence of confidentiality or integrity impact — the vulnerability is limited to availability (the server process terminates). Depending on the deployment context, a crashed FTP server could interrupt business-critical file transfer workflows and require manual intervention to restore service (VulnCheck Advisory, Exploit-DB).
A public proof-of-concept exploit for CVE-2023-53886 is available on Exploit-DB (EDB-51665), lowering the barrier for exploitation. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. No specific threat actor attribution has been reported (Exploit-DB, VulnCheck Advisory).
xlightftpd.exe or similar) from the process list without a scheduled restart..dmp) generated in the Xlight FTP Server installation directory or Windows error reporting folders following the crash event.Users should update Xlight FTP Server to the latest available version from the vendor's website, as a patch has been made available (Xlight FTP Vendor). As interim mitigations, administrators should restrict access to the Xlight FTP Server administration interface to trusted users only, implement input length validation or sanitization for the 'Execute Program' configuration field, and use network segmentation to limit exposure of the FTP server. Monitoring FTP server logs for unusual configuration changes or crash events is also recommended.
The vulnerability received routine coverage from vulnerability aggregation platforms and security feeds following its December 15, 2025 publication. A brief mention appeared on Bluesky via automated CVE tracking accounts, and the vulnerability was included in a CISA weekly vulnerability summary for the week of December 15, 2025 (Red Packet Security). No notable independent researcher commentary or significant media coverage has been identified beyond standard aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."