Vulnerability record · CVE-2006-4318 · published 24 August 2006
CVE-2006-4318: WFTPD Server buffer overflow via long SIZE commands
TTexas Imperial Software · Wftpd
WFTPD Server 3.23 contains a buffer overflow that is triggered by long SIZE commands sent to the FTP service. A remote attacker can corrupt memory and potentially execute arbitrary code on the server. The flaw is in an old FTP server product, but public exploit code exists and the EPSS score is high.
Description
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code exists and EPSS is very high, but the CVSS vector requires authentication, reducing the attack surface compared to an unauthenticated flaw.
What it is
WFTPD Server 3.23 contains a buffer overflow that is triggered by long SIZE commands sent to the FTP service. A remote attacker can corrupt memory and potentially execute arbitrary code on the server. The flaw is in an old FTP server product, but public exploit code exists and the EPSS score is high.
Impact
An attacker who can authenticate to the FTP service may execute arbitrary code with the privileges of the WFTPD process. This could lead to full compromise of the host running the FTP server.
Attack surface
The vulnerability is reached over the network through the FTP control channel by sending a crafted SIZE command. The CVSS vector indicates authentication is required (Au:S), so the attacker must have valid FTP credentials; no user interaction is needed.
Exploitation
Public exploit code is referenced in SecurityFocus, SecurityTracker and Exploit-DB, and EPSS is 0.62409 (99th percentile), indicating a high likelihood of exploitation. The CVE is not listed in CISA KEV.
What to do
- Upgrade WFTPD Server to a version later than 3.23 if available, or migrate to a supported FTP server.
- Restrict network access to the FTP service to trusted hosts and require strong authentication.
- Disable or block the SIZE command if the FTP server configuration allows command filtering.
- Monitor vendor advisories and apply any available patches or workarounds promptly.
Detection
- Inspect FTP server logs for SIZE commands with unusually long arguments.
- Use network IDS/IPS signatures to detect oversized SIZE commands on FTP control channels.
- Monitor for unexpected process crashes or restarts of the WFTPD service.
- Correlate FTP authentication logs with subsequent anomalous process activity on the server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-4318 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-4318), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.