← back
CVE-2025-4255mediumCWE-119CWE-120

PCMan FTP Server RMD Command buffer overflow

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 6.9epss 2.0%
from disclosure to weapon41 days
Published on NVDMay 5
1st PoC+41d
exploitation probability
2.0%top 21% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RMD Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected products
PCMan · FTP Server
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.