Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-10030

42
FAUCET Score

CVE-2012-10030 is a critical vulnerability in FreeFloat FTP Server that allows unauthenticated remote attackers to upload arbitrary files to sensitive system directories. This is due to critical design flaws including empty credential acceptance, default root C:\ drive access, and lack of restrictions on file type or destination. The vulnerability has a CVSS score of 9.8 (Critical) and allows for remote code execution with SYSTEM-level privileges, as attackers can upload executable payloads and .mof files that are automatically processed by WMI. While not in CISA's KEV catalog, a Metasploit module exists, indicating readily available exploit code, despite limited community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
1.0CPE matchmatch criteria
cpe:2.3:a:freefloat:freefloat_ftp_server:1.0:*:*:*:*:*:*:*
All Versions ImpactedCPE match
cpe:2.3:a:freefloat:ftp_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.55%
Probability of exploitation in next 30 days
EPSS Percentile
72.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Metasploit: FreeFloat FTP Server Arbitrary File Upload · Dec 7, 2012
This CVE's current EPSS score of 0.0155 is in the 60th percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

archive.org / details/tucows_367516_Freefloat_FTP_Server
Product
raw.githubusercontent.com / rapid7/metasploit-framework/master/modules/exploits/windows/ftp/freefloatftp_wbem.rb
Exploit
exploit-db.com / exploits/23226
Exploit
fortiguard.com / encyclopedia/ips/34209/freefloat-ftp-server-arbitrary-file-upload
Third Party Advisory
vulncheck.com / advisories/freefloat-ftp-server-arbitrary-file-upload
Third Party Advisory