Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
PoC: CVE-2025-34299-lab
Docker test environment for CVE-2025-34299 - Monsta FTP Pre-Auth RCE vulnerability
PoC: CVE-2025-34299
MonstaFTP Unauthenticated File Upload
PoC: Blackash-CVE-2025-34299
CVE-2025-34299
PoC: CVE-2025-34299
Detection for CVE-2025-34299
PoC: CVE-2025-34299
Monsta FTP Unauthenticated Arbitrary File Upload - Proof of Concept
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free