CVE-2025-34299
Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
- Published Nov 7, 2025
- CVSS 9.3 critical
- 72.9% chance of exploitation in the next 30 days (EPSS)
- A Metasploit module exploits it
Affected software
In the news
- Monsta FTP: An SSRF Blocklist That Forgot IPv6 Exists VulnCheck Blog ·