CVE-2018-25366
globalscape CuteFTP
CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut is created and launched.
- CVSS
- 8.6
- EPSS
- 0.18% 8.03% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.26