In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.Creditssuidpitacorn421Referenceshttps://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-j6g2-8fm3-rm8m