CVE-2025-34299
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-07

Last updated on: 2025-12-10

Assigner: VulnCheck

Description
Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-07
Last Modified
2025-12-10
Generated
2026-04-26
AI Q&A
2025-11-07
EPSS Evaluated
2026-04-25
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
monstaftp monsta_ftp to 2.11 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

Monsta FTP versions 2.11 and earlier have a security flaw that allows attackers to upload arbitrary files without authentication. By uploading a specially crafted file from a malicious (S)FTP server, attackers can execute arbitrary code on the affected system.


How can this vulnerability impact me? :

This vulnerability can lead to unauthorized code execution on your system, potentially allowing attackers to take control, compromise data integrity, disrupt services, or use the system as a foothold for further attacks.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart