CVE-2010-20113
EasyFTP Server 1.7.0.11 and earlier contains a stack-based buffer overflow vulnerability in its HTTP interface. When processing a GET request to list.html, the server fails to properly validate the length of the path parameter. Supplying an excessively long value causes a buffer overflow on the stack, potentially corrupting control flow structures. The vulnerability is exposed through the embedded web server and does not require authentication due to default anonymous access. The issue was resolved in version 1.7.0.12, after which the product was renamed to UplusFtp.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 62.71%
- CWE
- CWE-121
- Published
- 2025-08-21
- Last modified
- 2026-05-15
Affected products
- KMiNT21 Software EasyFTP Server
- KMiNT21 Software EasyFTP Server
Weakness type
Related vulnerabilities
- CVE-2026-78910 — Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside
- CVE-2026-75784 — TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow
- CVE-2026-79911 — TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow
- CVE-2026-77946 — TRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based overflow
- CVE-2026-86296 — D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow
- CVE-2026-76008 — Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow
- CVE-2026-74843 — Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow
- CVE-2026-16872 — Vulnerabilities in IBM AIX and PowerVM VIOS