Product Referenceproduct
https://en.softonic.com/download/nico-ftp/windows/post-download CVE-2018-25254
CRITICAL
NICO-FTP 3.0.1.19 Buffer Overflow SEH
Record summary
CVE-2018-25254 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
NICO-FTPBrowse nico-ftp / NICO-FTP | CVE List | 3.0.1.19 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBNICO-FTP 3.0.1.19 - Buffer Overflow (SEH)ExploitDB exploitby Abdullah AlıçNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25254 ExploitDB-45442exploit
https://www.exploit-db.com/exploits/45442 VulnCheck Advisory: NICO-FTP 3.0.1.19 Buffer Overflow SEHThird-party advisory
https://www.vulncheck.com/advisories/nico-ftp-buffer-overflow-seh