CVE-2025-34299
PoC nicheUnauthenticated Arbitrary File Upload RCE in Monsta FTP 2.11 and earlier
Monsta FTP versions 2.11 and earlier contain an unauthenticated arbitrary file upload flaw (CWE-434) that can be triggered remotely without any credentials or user interaction. An attacker can cause a specially crafted file to be uploaded from a malicious (S)FTP server that the Monsta FTP instance connects to, and the crafted upload ultimately allows execution of arbitrary code on the server hosting the web FTP client. Successful exploitation gives the attacker code execution with the privileges of the web application, which on typical shared hosting deployments can lead to compromise of hosted sites and stored credentials. Anyone running a self-hosted Monsta FTP instance at version 2.11 or earlier is affected, including instances embedded in hosting environments. A public proof-of-concept and technical write-up have been published by watchTowr Labs, the flaw is not yet listed in CISA KEV, and EPSS assigns a high 72.9% probability of exploitation within 30 days, indicating elevated near-term risk.
What to do: Upgrade Monsta FTP to the latest release newer than 2.11 as soon as a vendor-patched build is available, since the data does not specify a fixed version number. Until patched, restrict access to Monsta FTP (IP allow-listing, VPN, or an additional HTTP authentication layer in front of the application) and avoid connecting to untrusted (S)FTP servers. Review web server logs for unexpected or unauthenticated file writes/uploads and monitor watchTowr and vendor advisories for confirmation of in-the-wild exploitation.
| monstaftp monsta ftp | all versions 2.11 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
- Vendors
- monstaftp
- Products
- monsta ftp
- Weakness
- CWE-434
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.