PatchSiren

nico-ftp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL nico-ftp CVE published 2026-04-04

CVE-2018-25254

CVE-2018-25254 is a structured exception handler buffer overflow vulnerability in NICO-FTP 3.0.1.19. Remote attackers can execute arbitrary code by sending crafted FTP commands, specifically oversized data in response handlers, to overwrite SEH pointers and redirect execution to injected shellcode. This vulnerability has a CVSS score of 9.3 and is classified as CRITICAL. Users of NICO-FTP 3.0.1.19 should [truncated]