CRITICAL🇵🇱 Wersja polska

CVE-2025-34299

CVSS 9.3v4.0pub. 2025-11-07upd. 2025-12-10

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.

🤖 AI Analysis
How it works

The error classified as CWE-434 (unrestricted upload of file with dangerous type) consists of the lack of proper verification of uploaded files on the application side. An attacker can force the application to download and save a specially crafted file from a malicious (S)FTP server under their control. The file uploaded in this manner can contain an executable payload, which is then executed on the target server.

Impact

An attacker without any authentication can gain full control over the server through remote code execution (RCE). This results in potential system compromise, data theft, and the ability to perform lateral movement within the network.

Mitigation & patch

Monsta FTP must be immediately updated to a version newer than 2.11. Details regarding available patches can be found in the official manufacturer's notes at https://www.monstaftp.com/notes/. Until the update is applied, consider restricting network access to the Monsta FTP panel exclusively to trusted IP addresses.

Who is affected

Monsta FTP in version 2.11 and all earlier versions.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Monstaftp Monsta Ftp

    APP
    Monstaftp
    ≤ 2.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2022-27468CRITICAL9.8PL ✓same product

Dowolne przesyłanie plików w Monsta FTP umożliwiające RCE

CVE-2022-27469CRITICAL9.8PL ✓same product

SSRF w Monsta FTP v2.10.3 umożliwia nieautoryzowane żądania po stronie serwera

CVE-2020-14056CRITICAL9.8PL ✓same product

SSRF w Monsta FTP — odczyt plików lokalnych i dostęp do usług zewnętrznych

CVE-2020-14057CRITICAL9.8PL ✓same product

Monsta FTP — zewnętrzna kontrola ścieżek umożliwiająca RCE

CVE-2020-14055MEDIUM6.1same product

Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due...