EXECUTIVE SUMMARY:
A critical pre-auth remote code execution vulnerability exists in a popular web-based FTP client used by financial firms and large enterprises. The flaw lets an attacker force the client to fetch a malicious file from an attacker-controlled SFTP server and then write that file to any location on the host, giving complete control of the system. Around five thousand public instances were seen exposed, and the issue is being actively exploited.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A critical pre-auth remote code execution vulnerability exists in a popular web-based FTP client used by financial firms and large enterprises. The flaw lets an attacker force the client to fetch a malicious file from an attacker-controlled SFTP server and then write that file to any location on the host, giving complete control of the system. Around five thousand public instances were seen exposed, and the issue is being actively exploited.[emaillocker id="1283"]
CVE-2025-34299: This vulnerability allows pre-auth remote code execution on affected installs. The exploit works by making the web client connect to a malicious SFTP endpoint, downloading a specially crafted payload, and writing that payload to an arbitrary path on the server. Because the write step is uncontrolled, an attacker can place and execute code, gaining full system access. Multiple public instances remain exposed and active exploitation has been observed.
RECOMMENDATION:
We strongly recommend you upgrade Monsta FTP to version 2.11.3 or later.
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/monsta-ftp-remote-code-vulnerability/
[/emaillocker]