CVE-2010-20121 Details
Description
EasyFTP Server versions up to 1.7.0.11 contain a stack-based buffer overflow vulnerability in the FTP command parser. When processing the CWD (Change Working Directory) command, the server fails to properly validate the length of the input string, allowing attackers to overwrite memory on the stack. This flaw enables remote code execution without authentication, as EasyFTP allows anonymous access by default. The vulnerability was resolved in version 1.7.0.12, after which the product was renamed “UplusFtp.”
A stack-based buffer overflow vulnerability has been identified in EasyFTP Server versions through 1.7.0.11. The issue arises in the FTP command parser, specifically when the CWD (Change Working Directory) command is processed. The server does not properly validate the length of the input string, which allows attackers to overwrite memory on the stack. This vulnerability enables remote code execution without authentication, as EasyFTP allows anonymous access by default. The flaw was addressed in version 1.7.0.12, after which the product was renamed 'UplusFtp'.
Users are advised to upgrade to EasyFTP Server version 1.7.0.12 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| easyftp server project easyftp server | < 1.7.0.12 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2025 | Initial Analysis | [email protected] |
| Aug 22, 2025 | CVE Modified | CISA-ADP |
| Aug 21, 2025 | New CVE Received | [email protected] |