Ftpshell is a file-transfer application suite spanning server and client products that has surfaced with a notable tendency toward memory-safety vulnerabilities and elevated critical-severity outcomes. The vendor's exposure concentrates around buffer-overflow and memory-bounds-violation classes—improper buffer restrictions, out-of-bounds writes, and classic stack and heap overflows—that are characteristic of legacy native code and frequently acquire public exploit tooling. Live severity, exploitation activity, and current CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ftpshell over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7573CRITICAL An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with the FTP 220 response code to crash the application; after thi | Mar 1, 2018 | 9.8 | 84 | NO | YES |
CVE-2017-6465CRITICAL Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; however, it doesn't check the respon | Mar 10, 2017 | 9.8 | 70 | NO | YES |
CVE-2009-3364HIGH Stack-based buffer overflow in FTPShell Client 4.1 RC2 allows remote FTP servers to execute arbitrary code via a long response to a PASV command. | Sep 24, 2009 | 9.3 | 35 | NO | YES |
CVE-2009-0349HIGH Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (persistent daemon crash) and possibly execute arbitrary code | Jan 29, 2009 | 9.3 | 35 | NO | YES |
CVE-2019-25619HIGH FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by supplying a crafted strin | Mar 22, 2026 | 8.4 | 28 | NO | NO |
CVE-2020-18077HIGH A buffer overflow vulnerability in the Virtual Path Mapping component of FTPShell v6.83 allows attackers to cause a denial of service (DoS). | Dec 17, 2021 | 7.5 | 25 | NO | NO |
CVE-2018-25226MEDIUM FTPShell Server 6.83 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the account name field | Mar 30, 2026 | 6.2 | 22 | NO | NO |
FTPshell Server 3.38 allows remote authenticated users to cause a denial of service (application crash) by multiple connections and disconnections without using the QUIT command. | Aug 3, 2005 | 2.1 | 17 | NO | YES |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ftpshell.
Media articles that mention a CVE ID that affects a product developed by Ftpshell — matched by CVE ID, not by vendor name.