CVE-2026-67192

CRITICAL CVSS 4.0: 9.2 EPSS 0.62%
Updated Jul 30, 2026
Xlight
Parameter Value
CVSS 9.2 (CRITICAL)
Affected Versions before 3.9.5
Type CWE-121 (Stack-based Buffer Overflow)
Vendor Xlight
Public PoC No

Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length field passed directly to the GCM decrypt function, overwriting the stack cookie and return address to potentially achieve remote code execution before any authentication occurs.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0