AI description
CVE-2026-67192 is a pre-authentication stack buffer overflow vulnerability affecting Xlight FTP Server versions prior to 3.9.5. This flaw arises during the negotiation of a GCM cipher when handling SSH packets. Unauthenticated attackers can exploit this vulnerability by sending specially crafted SSH packets that contain an unvalidated length field. This malformed data is passed directly to the GCM decrypt function, leading to the corruption of stack memory, including the stack cookie and return address. This memory corruption can potentially enable remote code execution on the affected server before any authentication takes place.
- Description
- Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length field passed directly to the GCM decrypt function, overwriting the stack cookie and return address to potentially achieve remote code execution before any authentication occurs.
- Source
- disclosure@vulncheck.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 9.2
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- disclosure@vulncheck.com
- CWE-121
- Hype score
- Not currently trending
⚠️⚠️ CVE-2026-67191 (CVSS 9.8) + CVE-2026-67192 (CVSS 9.2): Pre-authentication buffer overflows in Xlight FTP Server allow unauthenticated RCE via malformed SSH packets before any login occurs 🔗FOFA Link: https://t.co/xESdsNJMk7 🎯60.5K+ Results are found on
@fofabot
5 Aug 2026
3473 Impressions
9 Retweets
19 Likes
10 Bookmarks
1 Reply
0 Quotes
🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-67192](https://t.co/hoOkacYoet... https://t.co/4u7GLPB6Bm #Vulnerability #CVE #ZeroDay
@MalwareObserver
30 Jul 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-67192 Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by send… https://t.co/Lu3Cv3vvAZ ----- Traducción: CVE-2026-67192 Xli… https://t.co/utmtNg
@infoflowcloud
29 Jul 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes