
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55058 is an Improper Input Validation vulnerability (CWE-20) affecting Maxum Rumpus FTP Server version 9.0.12. The vulnerability resides in a network-accessible component and can be exploited by unauthenticated remote attackers without user interaction. It was published on November 17, 2025, and assigned by INCD (Israel National Cyber Directorate). Feedly threat intelligence estimates a CVSS v3.1 base score of 9.8 (Critical), while the ENISA EUVD entry records an alternative scoring of 4.5 (Medium) under a different vector (Feedly, CIRCL).
The vulnerability is classified as CWE-20 (Improper Input Validation), meaning the Rumpus FTP Server fails to adequately validate or sanitize input received over the network before processing it. This allows an attacker to send specially crafted malicious input to the affected service component, potentially triggering unintended behavior such as denial of service, unauthorized access, or code execution. The attack vector is network-based, requires no privileges and no user interaction, and has low attack complexity, making it trivially exploitable from any network-accessible position. No public proof-of-concept or detailed technical write-up has been identified at this time (Feedly).
Successful exploitation of CVE-2025-55058 could result in complete system compromise, with high impact to confidentiality, integrity, and availability of the affected Rumpus FTP Server instance. An unauthenticated attacker could potentially access sensitive files managed by the FTP server, modify or corrupt data, or render the service unavailable. Given the FTP server's role in file transfer operations, exploitation could expose sensitive organizational data and serve as a foothold for lateral movement within the network (Feedly).
Patch availability for Maxum Rumpus 9.0.12 has not been confirmed in available data; administrators should monitor the Maxum vendor site for updates and apply any released patches immediately. As interim mitigations, implement network segmentation to restrict access to the Rumpus FTP service to only trusted hosts and IP ranges. Monitor FTP service logs for anomalous or malformed input patterns. If the FTP service is non-critical, consider disabling it until a patch is available. Apply perimeter-level input validation controls (e.g., WAF or network firewall rules) where feasible (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."