ZeroHour

CVE-2025-34299

PoC niche

Unauthenticated Arbitrary File Upload RCE in Monsta FTP 2.11 and earlier

CVSS 4.0
9.3 critical
EPSS
73%p99
Published
()
Modified
AI analysis

Monsta FTP versions 2.11 and earlier contain an unauthenticated arbitrary file upload flaw (CWE-434) that can be triggered remotely without any credentials or user interaction. An attacker can cause a specially crafted file to be uploaded from a malicious (S)FTP server that the Monsta FTP instance connects to, and the crafted upload ultimately allows execution of arbitrary code on the server hosting the web FTP client. Successful exploitation gives the attacker code execution with the privileges of the web application, which on typical shared hosting deployments can lead to compromise of hosted sites and stored credentials. Anyone running a self-hosted Monsta FTP instance at version 2.11 or earlier is affected, including instances embedded in hosting environments. A public proof-of-concept and technical write-up have been published by watchTowr Labs, the flaw is not yet listed in CISA KEV, and EPSS assigns a high 72.9% probability of exploitation within 30 days, indicating elevated near-term risk.

What to do: Upgrade Monsta FTP to the latest release newer than 2.11 as soon as a vendor-patched build is available, since the data does not specify a fixed version number. Until patched, restrict access to Monsta FTP (IP allow-listing, VPN, or an additional HTTP authentication layer in front of the application) and avoid connecting to untrusted (S)FTP servers. Review web server logs for unexpected or unauthenticated file writes/uploads and monitor watchTowr and vendor advisories for confirmation of in-the-wild exploitation.

Affected
monstaftp monsta ftpall versions 2.11 and earlier
Estimated exposure
nichelikely thousands to low tens of thousands of self-hosted instances (no public install counts available) — Monsta FTP is a self-hosted, often hosting-provider-embedded PHP web FTP client rather than a mass-market CMS plugin, and the data contains no active-install or internet-scan counts, so exposure is estimated from its deployment pattern as…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.

Vendors
monstaftp
Products
monsta ftp
Weakness
CWE-434
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.