CVE-2025-4255 EXPLOIT
7.3
HIGH · CVSS 3.1 · EPSS 2.1% (pctl 82)
Patch early
A public exploit exists.
Description
A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RMD Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Scoring
| CVSS | 7.3 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 2.14% — more likely to be exploited than 82% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2025-05-05 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| pcman | ftp server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PCMan FTP Server 2.0.7 - Buffer Overflow | 2025-06-15 |
References
→ the Explorer · watch your stack · NVD