nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25252 CVE-2018-25252
MEDIUM
FTP Voyager 16.2.0 Denial of Service via Malformed Site Profile
Record summary
CVE-2018-25252 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.
Description
FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can create a malicious site profile containing 500 bytes of repeated characters and paste it into the IP field to trigger a buffer overflow that crashes the FTP Voyager process.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FTP VoyagerBrowse Serv-U / FTP Voyager | CVE List | 16.2.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBFTP Voyager 16.2.0 - Denial of Service (PoC)ExploitDB exploitby Abdullah AlıçNot analyzed1 file
References
5ExploitDB-45527exploit
https://www.exploit-db.com/exploits/45527 Official Product Homepageproduct
https://www.serv-u.com/ Product Referenceproduct
https://www.serv-u.com/ftp-voyager VulnCheck Advisory: FTP Voyager 16.2.0 Denial of Service via Malformed Site ProfileThird-party advisory
https://www.vulncheck.com/advisories/ftp-voyager-denial-of-service-via-malformed-site-profile