---
id: CVE-2019-25588
title: BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address
summary: >-
  BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability
  in the DNS Address field that allows local attackers to crash the application
  by supplying an excessively long string. Attackers can enable the DNS Address
  opt…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: cna
cwe:
  - CWE-1282
vendor: Bpftpserver
product: BulletProof FTP Server
affected:
  - bulletproof_ftp_server 2019.0.0.50
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-03-24T14:01:17.488103Z'
exploitAvailable: true
published: '2026-03-22'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:19.736Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2019-25588'
references:
  - url: 'https://www.exploit-db.com/exploits/46875'
    label: ExploitDB-46875
  - url: 'http://bpftpserver.com/'
    label: Official Product Homepage
  - url: 'http://bpftpserver.com/products/bpftpserver/windows/download'
    label: Product Reference
  - url: >-
      https://www.vulncheck.com/advisories/bulletproof-ftp-server-denial-of-service-via-dns-address
    label: >-
      VulnCheck Advisory: BulletProof FTP Server 2019.0.0.50 Denial of Service
      via DNS Address
tags:
  - cve.org
  - exploit-available
epss: 0.00171
epssPercentile: 0.05833
ingestedAt: '2026-10-01T15:48:17.884Z'
---

## Overview

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.

## Affected

- `bulletproof_ftp_server 2019.0.0.50`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
