Back to search
CVE-2025-34107
Published: Jul 15, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
A buffer overflow vulnerability exists in the WinaXe FTP Client version 7.7 within the FTP banner parsing functionality, WCMDPA10.dll. When the client connects to a remote FTP server and receives an overly long '220 Server Ready' response, the vulnerable component responsible for parsing the banner overflows a stack buffer, leading to arbitrary code execution under the context of the user.
| Vendor | Product | Versions |
|---|---|---|
LabF | WinaXe FTP Client | affected 7.7 |
Weaknesses (CWE)
References
http://hyp3rlinx.altervista.org/advisories/WINAXE-FTP-CLIENT-REMOTE-BUFFER-OVERFLOW.txt
third-party-advisory
exploit
https://www.vulncheck.com/advisories/wina-xe-ftp-client-remote-buffer-overflow
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now