CVE-2024-0546

MEDIUM

EasyFTP 1.7.0 - Denial of Service via LIST Command Handler

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-0546. Includes Metasploit module exploits/windows/ftp/easyftp_list_fixret.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in EasyFTP Server 1.7.0.11 via the LIST command. It uses a fix-up stub to handle larger payloads and achieves remote code execution by overwriting the return address.

Description

A vulnerability, which was classified as problematic, has been found in EasyFTP 1.7.0. This issue affects some unknown processing of the component LIST Command Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250715.

Exploits (1)

metasploit WORKING POC GREAT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/ftp/easyftp_list_fixret.rb

This Metasploit module exploits a stack-based buffer overflow in EasyFTP Server 1.7.0.11 via the LIST command. It uses a fix-up stub to handle larger payloads and achieves remote code execution by overwriting the return address.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EasyFTP Server 1.7.0.11
Auth required
Prerequisites: Network access to the target FTP server · Valid credentials for authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory vdb-entry
https://vuldb.com/?id.250715
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.250715

Scores

CVSS v3 5.3
EPSS 0.0682
EPSS Percentile 93.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
easyftp/easyftp 1.7.0
Published Jan 15, 2024
Tracked Since Feb 18, 2026