PatchSiren cyber security CVE debrief
CVE-2018-25252 Serv-U CVE debrief
FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. This vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The vulnerability can be triggered by creating a malicious site profile containing 500 bytes of repeated characters and pasting it into the IP field, which causes a buffer overflow that crashes the FTP Voyager process. Users of FTP Voyager 16.2.0 should apply patches or mitigations to prevent local denial of service attacks.
- Vendor
- Serv-U
- Product
- FTP Voyager
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-04
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-04
- Advisory updated
- 2026-07-24
Who should care
Users of FTP Voyager 16.2.0 should apply patches or mitigations to prevent local denial of service attacks. This vulnerability has a CVSS score of 6.9 and a severity of MEDIUM, indicating a medium priority for remediation. Operators, administrators, and security teams responsible for FTP Voyager 16.2.0 deployments should review and implement mitigations to prevent exploitation.
Technical summary
FTP Voyager 16.2.0 has a denial of service vulnerability via site profile IP field. Local attackers can create a malicious site profile containing 500 bytes of repeated characters and paste it into the IP field to trigger a buffer overflow that crashes the FTP Voyager process. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The vulnerability affects the FTP Voyager 16.2.0 application and can be mitigated by applying patches or updates from the vendor.
Defensive priority
Medium priority due to local attack vector and potential for service disruption.
Recommended defensive actions
- Apply patches or updates from the vendor to address the vulnerability.
- Implement compensating controls such as limiting access to the site profile IP field.
- Monitor FTP Voyager logs for suspicious activity.
- Review and implement additional security controls to prevent similar vulnerabilities.
- Conduct regular vulnerability assessments and penetration testing to identify potential weaknesses.
- Develop and implement an incident response plan in case of a security breach.
- Verify that FTP Voyager 16.2.0 deployments are properly configured and secured.
Evidence notes
The CVE record and NVD details provide evidence of the vulnerability. Vendor advisories and exploit details are also available. The vulnerability affects FTP Voyager 16.2.0 and allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Evidence limits suggest that additional verification may be required to confirm affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2018-25252 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2018-25252
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2018-25252 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-25252
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/45527
[email protected] - Exploit, Third Party Advisory, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://www.serv-u.com/
[email protected] - Product
-
Source reference
Unverified legacy reference
URL: https://www.serv-u.com/ftp-voyager
[email protected] - Product
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/ftp-voyager-denial-of-service-via-malformed-site-profile
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.