CVE-2010-20045

HIGH

FileWrangler <= 5.30 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2010-20045. PoCs published by Metasploit, nullthreat, including Metasploit module exploits/windows/ftp/filewrangler_list_reply.

AI-analyzed exploit summary This exploit targets a stack buffer overflow in FileWrangler 5.30 via an overly long directory name in an FTP response. It uses an egghunter and SEH overwrite to achieve remote code execution.

Description

FileWrangler <= 5.30 suffers from a stack-based buffer overflow vulnerability when parsing directory listings from an FTP server. A malicious server can send an overlong folder name in response to a LIST command, triggering memory corruption during client-side rendering. Exploitation requires passive user interaction—simply connecting to the server—without further input. Successful exploitation may lead to arbitrary code execution.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16721

This exploit targets a stack buffer overflow in FileWrangler 5.30 via an overly long directory name in an FTP response. It uses an egghunter and SEH overwrite to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: FileWrangler 5.30
No auth needed
Prerequisites: Network access to the target · Target must connect to a malicious FTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
by nullthreat · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/ftp/filewrangler_list_reply.rb

This Metasploit module exploits a stack buffer overflow in FileWrangler 5.30 via an overly long directory name in an FTP response. It uses an egghunter to locate and execute the payload, bypassing space constraints.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: FileWrangler 5.30
No auth needed
Prerequisites: Attacker-controlled FTP server · Victim connects to the malicious FTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v4 8.5
EPSS 0.0032
EPSS Percentile 23.5%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (1)
CursorArts/FileWrangler < 5.30
Published Aug 20, 2025
Tracked Since Feb 18, 2026