CVE-2012-10055
ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By sending a specially crafted username containing format specifiers, a remote attacker can overwrite a hardcoded function pointer in memory (specifically WSACleanup from Ws2_32.dll). This allows the attacker to redirect execution flow and bypass DEP protections using a ROP chain, ultimately leading to arbitrary code execution. The vulnerability is exploitable without authentication and affects default configurations.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 58.95%
- CWE
- CWE-134
- Published
- 2025-08-13
- Last modified
- 2026-07-15
Affected products
- ComSndFTP FTP Server
Weakness type
Related vulnerabilities
- CVE-2024-23113 — A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
- CVE-2023-35086 — ASUS RT-AX56U V2 & RT-AC86U - Format String -1
- CVE-2020-3118 — Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
- CVE-2011-10029 — Solar FTP Server <= 2.1.1 Malformed USER Denial of Service
- CVE-2022-26674 — ASUS RT-AX88U - Format String
- CVE-2022-34747 — A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to ach
- CVE-2021-41193 — Use of Externally-Controlled Format String in wire-avs
- CVE-2023-35087 — ASUS RT-AX56U V2 & RT-AC86U - Format String - 2