Cyber Security News

Monsta web-based FTP Remote Code Execution Vulnerability Exploited

A critical remote code execution vulnerability in Monsta FTP, a popular web-based FTP client used by financial institutions and enterprises worldwide.

The flaw, now tracked as CVE-2025-34299, affects multiple versions of the software and has been exploited in the wild.

Monsta FTP is a browser-based file transfer client that allows users to manage files on remote servers without dedicated FTP software.

With at least 5,000 instances exposed on the internet, the platform serves a diverse user base, including financial organizations and large enterprises.

The Vulnerability and Patch Available

The security flaw enables attackers to achieve pre-authenticated remote code execution on vulnerable Monsta FTP servers.

WatchTowr Labs researchers discovered that despite developers adding extensive input validation functions in recent updates, critical vulnerabilities remained unpatched across multiple versions.

The attack works through a simple three-step process: An attacker tricks Monsta FTP into connecting to a malicious SFTP server. Downloads a crafted payload file.

Writes that file to an arbitrary path on the target server. This grants complete control over the vulnerable system.

CVE IDVulnerability TypeAffected VersionStatusExploitation
CVE-2025-34299Remote Code Execution (RCE)Monsta FTP ≤ 2.11.2Patched in v2.11.3 (Aug 26, 2025)Active exploitation in the wild

The vulnerability affects versions 2.10.3 through 2.11, and researchers found that previously reported security flaws were never properly fixed.

WatchTower Labs Analysis revealed minimal code changes between versions 2.10.3 and 2.10.4, leaving known vulnerabilities intact with version updates.

Monsta FTP released version 2.11.3 on August 26, 2025, which addresses this critical vulnerability.

Organizations running Monsta FTP should immediately upgrade to the latest version to protect their systems.

The discovery highlights ongoing security challenges in web-based file management systems, particularly when legacy vulnerabilities persist despite multiple software updates.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

2 hours ago

OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently

OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The…

2 hours ago

Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations

The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions…

2 hours ago

Salesforce Confirms that Customers’ Data Was Accessed Following the Gainsight Breach

Salesforce has issued a critical security alert identifying "unusual activity" involving Gainsight-published applications connected to…

4 hours ago

Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The notorious Clop ransomware gang has listed Oracle on its dark web leak site, alleging…

5 hours ago

Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image

A critical remote code execution flaw in Microsoft's Windows Graphics Component allows attackers to seize…

16 hours ago