EIP-2026-103125

PRE-CVE

Gopherd 3.0.5 - FTP Gateway Remote Overflow

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103125. PoCs published by vade79.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in UMN gopherd's FTP gateway feature, allowing remote code execution via a crafted FTP LIST response. It binds a shell on port 45295 and requires root privileges to bind to port 21 for the fake FTP daemon.

Description

Gopherd 3.0.5 - FTP Gateway Remote Overflow

Exploits (1)

exploitdb WORKING POC VERIFIED
by vade79 · cremotelinux
https://www.exploit-db.com/exploits/84

This exploit targets a buffer overflow vulnerability in UMN gopherd's FTP gateway feature, allowing remote code execution via a crafted FTP LIST response. It binds a shell on port 45295 and requires root privileges to bind to port 21 for the fake FTP daemon.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: UMN gopherd 2.x.x/3.x.x
No auth needed
Prerequisites: gopherd with FTP gateway support enabled · gopherd running as root or in root directory · attacker must run exploit as root to bind to port 21
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026