CVE-2026-67192
Xlight · Xlight FTP Server
Xlight FTP Server prior to 3.9.5 is vulnerable to a stack-based buffer overflow via the SSH GCM cipher.
Executive summary
Xlight FTP Server versions before 3.9.5 are susceptible to a pre-authentication stack-based buffer overflow, which could allow remote code execution.
Vulnerability
The application is vulnerable to a stack-based buffer overflow (CWE-121) occurring during the processing of SSH GCM ciphers. This allows unauthenticated remote attackers to trigger memory corruption and potentially execute arbitrary code on the server.
Business impact
This critical vulnerability allows for remote code execution without requiring user interaction or authentication. With a CVSS score of 8.1, the risk of total system compromise is high, potentially leading to unauthorized data access and the establishment of persistent backdoors within the network infrastructure.
Remediation
Immediate Action: Update Xlight FTP Server to version 3.9.5 or later immediately.
Proactive Monitoring: Monitor server logs for abnormal crash events or unusual SSH connection attempts that may indicate attempts to trigger the buffer overflow.
Compensating Controls: Restrict access to the FTP server to trusted IP addresses only and utilize a firewall to drop suspicious connection requests.
Exploitation status
Public Exploit Available: No confirmed public exploit.
Analyst recommendation
Given the potential for remote code execution, this vulnerability poses a severe risk to any environment hosting Xlight FTP Server. Organizations must prioritize upgrading to version 3.9.5 to patch the buffer overflow and protect against potential remote exploitation.