Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-5548 — Structured lab for controlled exploitation of CVE-2025-5548 (FreeFloat FTP Server). Includes environment setup, fuzzing, EIP control, badchars detection, JMP ESP redirection, and final shellcode delivery via Python scripts. | Kitploit
Tools/GitHubGitHub/diego57709/cve-2025-5548
Vulnerability AnalysisExploitationReverse EngineeringShellcodeDebuggersFuzzingPenetration TestingLearning & EducationPayload DevelopmentBinary ExploitationLabs & Practice
166 months agoNot yet reviewed
GitHub
diego57709/cve-2025-5548

CVE-2025-5548

Structured lab for controlled exploitation of CVE-2025-5548 (FreeFloat FTP Server). Includes environment setup, fuzzing, EIP control, badchars detection, JMP ESP redirection, and final shellcode delivery via Python scripts.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Exploitation Lab - CVE-2025-5548 (FreeFloat FTP)

Repository for a controlled exploitation lab of CVE-2025-5548 on FreeFloat FTP Server, running on Windows inside an isolated VM.

The project is divided into two blocks:

  • Environment/: environment setup (tools, IDEs, debugger, disassembler, and vulnerable apps).
  • Exploit/: practical methodology and scripts for a complete exploitation chain of the FTP vector (MKD) associated with the CVE scenario.

Lab Objective

Build, validate, and document a reproducible exploitation chain that covers:

  1. Connectivity verification and vulnerable surface.
  2. Fuzzing and stable crash reproduction.
  3. EIP control and exact offset calculation.
  4. Badchars identification.
  5. Flow redirection with JMP ESP.
  6. Final payload delivery in a practice environment.

Scope and context

  • Case study: CVE-2025-5548 on FreeFloat FTP Server.
  • Environment: controlled local lab.
  • Working architecture: x86 with debugging in Immunity Debugger + Mona.

Current Repository Structure

M6/
├── README.md
├── Environment/
│   ├── 01-requirements/
│   │   └── requirements.md
│   ├── 02-programming-environment/
│   │   ├── git.md
│   │   ├── java-jdk.md
│   │   ├── netcat.md
│   │   └── python3.md
│   ├── 03-ides/
│   │   ├── notepad++.md
│   │   ├── pycharm.md
│   │   └── vscode.md
│   ├── 04-debuggers/
│   │   └── immunity-debugger.md
│   ├── 05-disassemblers/
│   │   ├── ghidra.md
│   │   └── ida-free.md
│   ├── 06-exploit-development/
│   │   └── mona-immunity.md
│   ├── 07-vulnerable-applications/
│   │   ├── freefloatftpserver.md
│   │   └── vulnserver.md
│   └── images/
│       └── README.md
└── Exploit/
	├── metodologia-analisis.md
	├── Scripts/
	│   ├── 01_check_connection.py
	│   ├── 02_fuzz_trun.py
	│   ├── 03_send_pattern.py
	│   ├── 04_verify_eip_control.py
	│   ├── 05_send_badchars.py
	│   ├── 06_test_jmp_esp.py
	│   └── 07_final_payload.py
	└── images/

Environment Documentation

BlockResource
Requirementsrequirements.md
Programminggit.md, java-jdk.md, netcat.md, python3.md
IDEsnotepad++.md, pycharm.md, vscode.md
Debuggerimmunity-debugger.md
Disassemblersghidra.md, ida-free.md
Exploit toolingmona-immunity.md
Vulnerable appsfreefloatftpserver.md, vulnserver.md

CVE Exploitation Flow (current state)

Full methodology: metodologia-analisis.md

Current scripts:

  1. 01_check_connection.py: validates connectivity and service banner.
  2. 02_fuzz_trun.py: incremental fuzzing of the MKD command.
  3. 03_send_pattern.py: sends cyclic pattern generated by Mona.
  4. 04_verify_eip_control.py: validates EIP control (BBBB).
  5. 05_send_badchars.py: sends bytearray.bin to detect badchars.
  6. 06_test_jmp_esp.py: tests return with JMP ESP address.
  7. 07_final_payload.py: sends final payload with shellcode.

Lab Assumptions

  • Isolated test environment (Windows VM).
  • Target service FreeFloat FTP on 127.0.0.1:21.
  • Debugging with Immunity Debugger + Mona.

Responsible Use Note

This lab is designed for technical learning, control validation, and authorized testing on your own environment. It must not be used on systems without explicit permission.

Quick Execution

From the repo root:

cd Exploit
python .\Scripts\01_check_connection.py
python .\Scripts\02_fuzz_trun.py
python .\Scripts\03_send_pattern.py
python .\Scripts\04_verify_eip_control.py
python .\Scripts\05_send_badchars.py
python .\Scripts\06_test_jmp_esp.py
python .\Scripts\07_final_payload.py

Note: for 03_send_pattern.py and 05_send_badchars.py you must have Mona configured and the files in C:\mona\.

Download Tool