CVE-2026-67192

Published Jul 29, 2026

Last updated 20 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-67192 is a pre-authentication stack buffer overflow vulnerability affecting Xlight FTP Server versions prior to 3.9.5. This flaw arises during the negotiation of a GCM cipher when handling SSH packets. Unauthenticated attackers can exploit this vulnerability by sending specially crafted SSH packets that contain an unvalidated length field. This malformed data is passed directly to the GCM decrypt function, leading to the corruption of stack memory, including the stack cookie and return address. This memory corruption can potentially enable remote code execution on the affected server before any authentication takes place.

Description
Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length field passed directly to the GCM decrypt function, overwriting the stack cookie and return address to potentially achieve remote code execution before any authentication occurs.
Source
disclosure@vulncheck.com
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

disclosure@vulncheck.com
CWE-121

Social media

Hype score
Not currently trending