PT-2025-50971 · Pcman · Pcman Ftp Server

Published

2025-12-12

·

Updated

2025-12-13

·

CVE-2024-58299

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PCMan FTP Server version 2.0
Description PCMan FTP Server 2.0 contains a buffer overflow in the 'pwd' command. This allows remote attackers to execute arbitrary code by sending a specially crafted payload during the FTP login process, potentially gaining system access. The vulnerability is exploitable before authentication. The 'pwd' command is susceptible to a stack-based buffer overflow.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-58299

Affected Products

Pcman Ftp Server