Vulnerability record · CVE-2001-0550 · published 30 November 2001
CVE-2001-0550: wu-ftpd glob handling flaw allows remote command execution
DDavid Madore · Ftpd Bsd
wu-ftpd 2.6.1 fails to properly handle a "~{" argument passed to FTP commands such as CWD, because the glob function (ftpglob) mishandles it. A remote attacker can therefore execute arbitrary commands on the FTP server. The flaw is remotely reachable and rated HIGH (CVSS 2.0 7.5), making it a serious risk for any exposed wu-ftpd service.
Description
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated command execution with public exploit code and very high EPSS, though the product is legacy and not in KEV.
What it is
wu-ftpd 2.6.1 fails to properly handle a "~{" argument passed to FTP commands such as CWD, because the glob function (ftpglob) mishandles it. A remote attacker can therefore execute arbitrary commands on the FTP server. The flaw is remotely reachable and rated HIGH (CVSS 2.0 7.5), making it a serious risk for any exposed wu-ftpd service.
Impact
An attacker gains arbitrary command execution on the FTP server, typically in the context of the ftpd process, which can lead to full host compromise. No confidentiality, integrity or availability impact is excluded by the vector; all three are partial.
Attack surface
Reached over the network via the FTP service by sending a crafted "~{" argument to commands such as CWD. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.74762, 99.5th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists.
What to do
- Patch or upgrade wu-ftpd to a fixed release per the vendor advisories (Red Hat RHSA-2001-157, Caldera CSSA-2001-041, Debian DSA-087, CERT CA-2001-33).
- If patching is not possible, disable or restrict anonymous and untrusted FTP access, or replace wu-ftpd with a maintained FTP server.
- Block or filter FTP traffic from untrusted networks at the perimeter until the service is patched.
- Audit the FTP service account's privileges and file system access to limit the blast radius of command execution.
Detection
- Inspect FTP command logs for arguments containing "~{" or unusual glob metacharacters in CWD and similar commands.
- Monitor for unexpected child processes or shell activity spawned by the ftpd process.
- Alert on FTP sessions from unexpected source addresses or with anomalous command sequences.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2001-0550 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0550), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.