{"api_version":"1","generated_at":"2026-07-23T13:49:12+00:00","cve":"CVE-2020-14057","urls":{"html":"https://cve.report/CVE-2020-14057","api":"https://cve.report/api/cve/CVE-2020-14057.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-14057","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-14057"},"summary":{"title":"CVE-2020-14057","description":"Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-07-01 17:15:00","updated_at":"2020-07-08 13:18:00"},"problem_types":["CWE-610"],"metrics":[],"references":[{"url":"https://www.monstaftp.com/notes/","name":"https://www.monstaftp.com/notes/","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Release Notes - Monsta FTP","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/sbaresearch/advisories/tree/public/2019/SBA-ADV-20191203-01_Monsta_FTP_Arbitrary_File_Read_and_Write","name":"https://github.com/sbaresearch/advisories/tree/public/2019/SBA-ADV-20191203-01_Monsta_FTP_Arbitrary_File_Read_and_Write","refsource":"MISC","tags":["Third Party Advisory"],"title":"advisories/2019/SBA-ADV-20191203-01_Monsta_FTP_Arbitrary_File_Read_and_Write at public · sbaresearch/advisories · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-14057","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-14057","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"14057","vulnerable":"1","versionEndIncluding":"2.10.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"monstaftp","cpe5":"monsta_ftp","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-14057","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.monstaftp.com/notes/","refsource":"MISC","name":"https://www.monstaftp.com/notes/"},{"refsource":"MISC","name":"https://github.com/sbaresearch/advisories/tree/public/2019/SBA-ADV-20191203-01_Monsta_FTP_Arbitrary_File_Read_and_Write","url":"https://github.com/sbaresearch/advisories/tree/public/2019/SBA-ADV-20191203-01_Monsta_FTP_Arbitrary_File_Read_and_Write"}]}},"nvd":{"publishedDate":"2020-07-01 17:15:00","lastModifiedDate":"2020-07-08 13:18:00","problem_types":["CWE-610"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:monstaftp:monsta_ftp:*:*:*:*:*:*:*:*","versionEndIncluding":"2.10.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"14057","Ordinal":"175283","Title":"CVE-2020-14057","CVE":"CVE-2020-14057","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"14057","Ordinal":"1","NoteData":"Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"14057","Ordinal":"2","NoteData":"2020-07-01","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"14057","Ordinal":"3","NoteData":"2020-07-01","Type":"Other","Title":"Modified"}]}}}