CVE-2025-34110 - CVE House
Back to Database
Status published Critical CVE-2025-34110

ColoradoFTP Server <= 1.3 Build 8 Path Traversal Information Disclosure

Vulnerability Description

A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbitrary files outside the configured FTP root directory. The flaw is due to insufficient sanitation of user-supplied file paths in the FTP GET and PUT command handlers. Exploitation is possible by submitting traversal sequences during FTP operations, enabling access to system-sensitive files. This issue affects only the Windows version of ColoradoFTP.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34110

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • RvLaboratory