Monsta FTP Remote Code Execution Vulnerability CVE-2025-34299 Discovered
First seen 23 Nov 2025, 03:35 UTC
•
•55.5
Export
Article Content
Browse articles
A critical remote code execution vulnerability (CVE-2025-34299) has been identified in Monsta FTP, a web-based file transfer client, allowing unauthenticated attackers to execute arbitrary code on affected systems. The flaw arises from improper handling of user input during file downloads, endangering thousands of servers. Researchers have confirmed that this vulnerability is being actively exploited in the wild.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Logitech Confirms Data Breach from Zero-Day Exploit by Clop Gang
Washington Post Confirms Breach from Oracle EBS Attacks by Cl0p Ransomware Gang
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure