PT-2026-65837 · Unknown · Xlight Ftp Server

CVE-2026-67192

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xlight FTP Server versions prior to 3.9.5
Description A pre-authentication stack buffer overflow occurs when a GCM cipher is negotiated. Unauthenticated attackers can corrupt stack memory by sending malformed SSH packets containing an unvalidated length field. This field is passed directly to the GCM decrypt function, allowing the overwriting of the stack cookie and return address, which can lead to remote code execution.
Recommendations Update Xlight FTP Server to version 3.9.5 or later.

Fix

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67192

Affected Products

Xlight Ftp Server