Back

CRITICAL

ProFTPD 1.3.3c Backdoor Command Execution

Published Aug 20, 2025

Description

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 20, 2025
Updated Jul 15, 2026
Reserved Aug 19, 2025
CISA Vulnrichment
Updated Aug 22, 2025
NVD
Status Analyzed
Modified Jul 15, 2026
Red Hat
Severity n/a
Public date n/a