Pcman's vulnerability footprint centers on a lightweight FTP server product that, despite a narrow portfolio, has accumulated a substantial vulnerability record within a prominence tier that reflects its embedded deployment in legacy and resource-constrained systems. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, driven by the recurrence of classic memory-safety defects: buffer overflows, improper bounds checking, and out-of-bounds writes that are characteristic of native-code network daemons written without modern protections. The concentration of these weakness classes in a network-facing service means that individual flaws frequently permit remote code execution, elevating risk even where deployment footprint may appear modest. Defenders should inventory Pcman FTP installations, treat available patches as urgent, and consider network segmentation to isolate legacy FTP services; current exploitation activity and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pcman over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-4255CRITICAL A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RMD Command Handler. The manipulation leads to buffer | May 5, 2025 | 9.8 | 40 | NO | YES |
CVE-2025-4240CRITICAL A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown processing of the component LCD Command Handler. The manipulatio | May 3, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-4184CRITICAL A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component QUOTE Command Handler. The manipulation leads t | May 2, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-4181CRITICAL A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component SEND Command Hand | May 1, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-3762CRITICAL A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unknown functionality of the component MPUT Command Handler. The | Apr 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-3380CRITICAL A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. Affected by this issue is some unknown functionality of the component FEAT Command Hand | Apr 7, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-3378CRITICAL A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component EPRT Command Handler. The manipulation leads to bu | Apr 7, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-5637CRITICAL A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component SYSTEM Command Handler. The manipulation le | Jun 5, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-5636CRITICAL A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SET Command Handler. The ma | Jun 5, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-4290CRITICAL A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SMNT Command Handler. The m | May 5, 2025 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pcman.
Media articles that mention a CVE ID that affects a product developed by Pcman — matched by CVE ID, not by vendor name.