No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 30 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xlightftpd
Xlightftpd xlight Ftp Server |
|
| Vendors & Products |
Xlightftpd
Xlightftpd xlight Ftp Server |
Wed, 29 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command with a username ending in the :adm suffix. Attackers can trigger the admin protocol path within the standard FTP listener pre-authentication to leak timing information from the FTP 331 response without requiring a separate port or configuration change. | |
| Title | Xlight FTP Server < 3.9.5 Information Disclosure via USER Command | |
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-29T17:53:59.797Z
Reserved: 2026-07-28T16:06:49.774Z
Link: CVE-2026-67193
Updated: 2026-07-29T17:53:53.692Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T15:15:03Z