{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/xlight/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-67192"},{"cvss":9.8,"id":"CVE-2026-67191"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Xlight FTP Server","Xlight FTP Server (\u003c 3.9.5)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","buffer-overflow","ftp"],"_cs_type":"advisory","_cs_vendors":["Xlight"],"content_html":"\u003cp\u003eXlight FTP Server versions prior to 3.9.5 are susceptible to a pre-authentication stack-based buffer overflow vulnerability (CVE-2026-67192). The vulnerability exists within the SSH implementation of the server, specifically when handling GCM (Galois/Counter Mode) cipher negotiation. An unauthenticated attacker can send a maliciously crafted SSH packet containing an unvalidated length field to the GCM decryption routine. This oversight allows the attacker to corrupt the stack memory, specifically overwriting the stack cookie and the return address. Successful exploitation permits the attacker to achieve remote code execution before the authentication process is ever completed. This flaw poses a high risk as it requires no credentials and can be triggered during the initial stages of an SSH session.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker establishes an unauthenticated TCP connection to the Xlight FTP Server on the configured SSH port.\u003c/li\u003e\n\u003cli\u003eThe attacker initiates the SSH version exchange and key exchange (KEX) process.\u003c/li\u003e\n\u003cli\u003eThe attacker requests the use of a GCM cipher suite during the SSH negotiation phase.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a specially crafted SSH packet containing a manipulated length field that exceeds expected boundaries.\u003c/li\u003e\n\u003cli\u003eThe Xlight FTP Server's GCM decryption function processes the unvalidated length field, resulting in a stack buffer overflow.\u003c/li\u003e\n\u003cli\u003eThe overflow overwrites critical stack memory, including the stack canary and the function return address.\u003c/li\u003e\n\u003cli\u003eThe function execution returns to an attacker-controlled address or a gadget chain.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves arbitrary code execution on the server host with the privileges of the FTP service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-67192 allows unauthenticated remote attackers to gain code execution on affected Xlight FTP servers. This compromises the integrity and confidentiality of the entire server environment, potentially allowing for data exfiltration, lateral movement within the network, or the installation of persistent backdoors. Organizations running exposed Xlight FTP services prior to version 3.9.5 are at risk of complete system compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade Xlight FTP Server to version 3.9.5 or later to remediate CVE-2026-67192.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, restrict network access to the Xlight FTP server to trusted IP addresses using a firewall.\u003c/li\u003e\n\u003cli\u003eDeploy network-based intrusion detection signatures capable of inspecting SSH KEX packets for anomalous length values or malformed GCM negotiation structures.\u003c/li\u003e\n\u003cli\u003eMonitor server logs for unexpected crashes or service restarts which may indicate failed or repeated exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T16:21:02Z","date_published":"2026-07-29T16:18:31Z","id":"https://feed.craftedsignal.io/briefs/2026-07-xlight-ftp-rce/","summary":"Xlight FTP Server versions prior to 3.9.5 contain a pre-authentication stack buffer overflow vulnerability triggered by malformed SSH packets, potentially leading to remote code execution.","title":"Pre-Authentication Remote Code Execution in Xlight FTP Server","url":"https://feed.craftedsignal.io/briefs/2026-07-xlight-ftp-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Xlight","version":"https://jsonfeed.org/version/1.1"}