CVE-2026-67192

Xlight · Xlight FTP Server

Xlight FTP Server prior to 3.9.5 is vulnerable to a stack-based buffer overflow via the SSH GCM cipher.

Executive summary

Xlight FTP Server versions before 3.9.5 are susceptible to a pre-authentication stack-based buffer overflow, which could allow remote code execution.

Vulnerability

The application is vulnerable to a stack-based buffer overflow (CWE-121) occurring during the processing of SSH GCM ciphers. This allows unauthenticated remote attackers to trigger memory corruption and potentially execute arbitrary code on the server.

Business impact

This critical vulnerability allows for remote code execution without requiring user interaction or authentication. With a CVSS score of 8.1, the risk of total system compromise is high, potentially leading to unauthorized data access and the establishment of persistent backdoors within the network infrastructure.

Remediation

Immediate Action: Update Xlight FTP Server to version 3.9.5 or later immediately.

Proactive Monitoring: Monitor server logs for abnormal crash events or unusual SSH connection attempts that may indicate attempts to trigger the buffer overflow.

Compensating Controls: Restrict access to the FTP server to trusted IP addresses only and utilize a firewall to drop suspicious connection requests.

Exploitation status

Public Exploit Available: No confirmed public exploit.

Analyst recommendation

Given the potential for remote code execution, this vulnerability poses a severe risk to any environment hosting Xlight FTP Server. Organizations must prioritize upgrading to version 3.9.5 to patch the buffer overflow and protect against potential remote exploitation.