PT-2026-65838 · Unknown · Xlight Ftp Server

CVE-2026-67193

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xlight FTP Server versions prior to 3.9.5
Description An information disclosure issue exists where unauthenticated attackers can obtain the server's current GetTickCount() value. This is achieved by sending a USER command with a username ending in the :adm suffix, which triggers the admin protocol path within the standard FTP listener during pre-authentication. This process leaks timing information from the FTP 331 response without requiring a separate port or configuration change.
Recommendations Update Xlight FTP Server to version 3.9.5 or later.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67193

Affected Products

Xlight Ftp Server