PT-2026-65838 · Unknown · Xlight Ftp Server
CVE-2026-67193
·
Published
2026-07-29
·
Updated
2026-07-29
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Xlight FTP Server versions prior to 3.9.5
Description
An information disclosure issue exists where unauthenticated attackers can obtain the server's current
GetTickCount() value. This is achieved by sending a USER command with a username ending in the :adm suffix, which triggers the admin protocol path within the standard FTP listener during pre-authentication. This process leaks timing information from the FTP 331 response without requiring a separate port or configuration change.Recommendations
Update Xlight FTP Server to version 3.9.5 or later.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xlight Ftp Server