---
id: CVE-2018-25254
title: >-
  NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow
  vulnerability that allows remote attackers to execute arbitrary code by
  sending crafted FTP commands
summary: >-
  NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow
  vulnerability that allows remote attackers to execute arbitrary code by
  sending crafted FTP commands. Attackers can connect to the FTP service and
  send oversized d…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: nico-ftp_project
product: nico-ftp
affected:
  - nico-ftp <= 3.0.1.19
published: '2026-04-04'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25254'
references:
  - url: 'https://en.softonic.com/download/nico-ftp/windows/post-download'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/45442'
    label: disclosure@vulncheck.com
  - url: 'https://www.vulncheck.com/advisories/nico-ftp-buffer-overflow-seh'
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00914
epssPercentile: 0.58816
ingestedAt: '2026-10-06T22:23:15.916Z'
---

## Overview

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.

## Affected

- `nico-ftp <= 3.0.1.19`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
