CVE-2025-34110 Details
Description
A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbitrary files outside the configured FTP root directory. The flaw is due to insufficient sanitation of user-supplied file paths in the FTP GET and PUT command handlers. Exploitation is possible by submitting traversal sequences during FTP operations, enabling access to system-sensitive files. This issue affects only the Windows version of ColoradoFTP.
A directory traversal vulnerability has been identified in ColoradoFTP Server versions through 1.3 Build 8 for Windows. This vulnerability allows unauthenticated attackers to read or write arbitrary files outside the designated FTP root directory. The issue arises from inadequate sanitization of user-supplied file paths in the FTP GET and PUT command handlers. Exploitation can be achieved by sending traversal sequences during FTP operations, granting access to sensitive system files. This vulnerability is exclusive to the Windows version of ColoradoFTP.
Users are advised to upgrade to ColoradoFTP Prime Edition Build 9, which addresses this vulnerability. The updated version can be downloaded from the ColoradoFTP website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 15, 2025CISA-ADP
Assessed Jul 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-552 | Files or Directories Accessible to External Parties | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ColoradoFTP Server | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2025 | CVE Modified | [email protected] |
| Jul 15, 2025 | New CVE Received | [email protected] |
Volerion