CVE-2010-20103
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 85.08%
- CWE
- CWE-912
- Published
- 2025-08-20
- Last modified
- 2026-07-15
Affected products
- ProFTPD Project ProFTPD (Professional FTP Daemon)
Weakness type
Related vulnerabilities
- CVE-2024-20439 — A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an a
- CVE-2011-10018 — myBB 1.6.4 Backdoor Arbitrary Command Execution
- CVE-2025-34117 — Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
- CVE-2026-3587 — Hidden CLI Function Allows Root Access
- CVE-2024-39754 — A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafte
- CVE-2024-45697 — D-Link WiFi router - Hidden Functionality
- CVE-2020-12504 — Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
- CVE-2022-3203 — ORing net IAP-420(+) Hidden Functionality