Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-67193

Опубликовано: 29 июл. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command with a username ending in the :adm suffix. Attackers can trigger the admin protocol path within the standard FTP listener pre-authentication to leak timing information from the FTP 331 response without requiring a separate port or configuration change.

EPSS

Процентиль: 18%
0.00264
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 5.3
github
8 дней назад

Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command with a username ending in the :adm suffix. Attackers can trigger the admin protocol path within the standard FTP listener pre-authentication to leak timing information from the FTP 331 response without requiring a separate port or configuration change.

EPSS

Процентиль: 18%
0.00264
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203