PT-2026-24573 · Unknown · Swiftp Ftp Server+1
Vulncheck
+1
·
Published
2026-03-11
·
Updated
2026-05-11
·
CVE-2026-29515
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MiCode FileExplorer (affected versions not specified)
Description
The software contains an authentication bypass in the embedded SwiFTP FTP server component. This allows network attackers to log in without valid credentials by sending arbitrary username and password combinations to the
PASS command handler, which unconditionally grants access. Successful exploitation allows attackers to list, read, write, and delete files exposed by the FTP server. The MiCode/Explorer open source project has reached end-of-life status.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Micode Fileexplorer
Swiftp Ftp Server