#MonstaFTP
🚨 A critical Monsta FTP flaw (CVE-2025-34299) is still exposing hundreds of servers weeks after disclosure. Many remain unpatched and internet-facing.

Full article 👉 basefortify.eu/posts/2025/1...

#CyberSecurity #CVE2025 #MonstaFTP #RCE #BaseFortify
November 25, 2025 at 12:36 PM
A pre-auth RCE vulnerability (CVE-2025-34299) in #MonstaFTP lets attackers drop web shells and seize full control of servers. Over 5 000 instances exposed online. Update to version 2.11.3 or later now 📌

🔗 Read: hackread.com/monsta-ftp-f...

#CyberSecurity #InfoSec #Vulnerability #RCE
Monsta FTP Vulnerability Exposed Thousands of Servers to Full Takeover
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
November 10, 2025 at 10:58 AM
Critical RCE vulnerability (CVE-2025-34299) found in Monsta FTP. Immediate update to version 2.11.3 recommended to prevent exploitation. #CyberSecurity #MonstaFTP #RCE #Vulnerability Link: thedailytechfeed.com/critical-vul...
November 11, 2025 at 6:43 PM
⚠️ CVE-2025-34299 lets attackers upload malicious files and gain remote code execution. Shadowserver still sees ~800 vulnerable Monsta FTP servers exposed today.

More technical details here ⬇️
basefortify.eu/cve_reports/...

#InfoSec #CVE2025 #MonstaFTP #RCE #CyberAlert
November 25, 2025 at 12:36 PM
⚠️ monsta ftp flaw under active exploitation

CVE-2025-34299 enables unauthenticated RCE in Monsta FTP ≤ 2.11.2 via crafted POST requests abusing downloadFile.
Attackers can upload payloads and gain full server control.

Patch to v2.11.3 immediately.

#ransomNews #MonstaFTP #CVE202534299
November 10, 2025 at 1:37 PM
Introducing Our New Web-Based File Manager
redsusvn: > it is impossible to rename It is possible, the option is just well hidden. See my other comment. redsusvn: > copy That’s indeed missing. redsusvn: > cut, paste There is the option to move files. How is that different? redsusvn: > properties We have that. What are you missing specifically? redsusvn: > does not have right click menu for easy access My MonstaFTP muscle memory is missing this one too. But I don’t think that a right click menu is that critical. Keep in mind that they don’t really work on mobile, so having a different UI that works better on all devices is a cleaner way to implement it. Not your preference? I get that. Worst thing on the planet? That’s a bit of a stretch. redsusvn: > no way to zip a file If you select multiple files and click Download, you’ll get a zip file. There is not much point in zipping a single file. redsusvn: > extract the file if it already exist The focus was put on upload+unzip. That’s way more practical given the file size limits on our hosting. redsusvn: > and the worst part is the url contain user and token That’s being worked on and probably 90% done by now. I agree that this is not a very secure way, but many file managers work like this. MonstaFTP has it too, it’s their recommended way to do logins from control panels. Again, “worst on the planet” is a bit of a stretch here consider that this is basically the default. redsusvn: > to complicated stuff (their support website) That one has existed for many years with no major changes to it (as far as I know), long before AI coding was ever a thing. I also agree here that a standalone support portal with no link to the rest of the system (e.g. SSO) is not the best UX. But this just shows again that you can have good design and bad design with and without AI. redsusvn: > definally make you want to leave that site after 5s Meanwhile, we have Filestash with their mandatory nyan-cat loader (cringe), and just a lot of ancient software that hasn’t been getting a lot of love. Even cPanel’s file manager looks very outdated. You clearly seem to have a deep hatred for it. But the market for file managers just has a lot of bad options.
forum.infinityfree.com
October 7, 2025 at 2:04 PM