← Vulnerability feed

Vulnerability record · CVE-2009-4006 · published 20 November 2009

CVE-2009-4006: Serv-U FTP Server TEA Decoding Stack Buffer Overflow

Solarwinds · Serv U File Server

RhinoSoft Serv-U FTP server versions before 9.1.0.0 contain a stack-based buffer overflow in the TEA decoding algorithm. A remote attacker can trigger the overflow by sending a long hexadecimal string, which may corrupt the stack and allow arbitrary code execution. The flaw is remotely reachable and carries a maximum CVSS v2 base score of 10.0.

10.0 CVSS 2.0 High EPSS 83% · top 0.3% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityThe CVSS v2 score is 10.0 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, and EPSS is extremely high at 0.82932.

What it is

RhinoSoft Serv-U FTP server versions before 9.1.0.0 contain a stack-based buffer overflow in the TEA decoding algorithm. A remote attacker can trigger the overflow by sending a long hexadecimal string, which may corrupt the stack and allow arbitrary code execution. The flaw is remotely reachable and carries a maximum CVSS v2 base score of 10.0.

Impact

Successful exploitation can allow a remote attacker to execute arbitrary code in the context of the Serv-U FTP service. That could lead to full compromise of the FTP server host, including data theft, service disruption, or use as a pivot point.

Attack surface

The vulnerability is network-reachable (AV:N) with low attack complexity and no authentication required (Au:N), based on the CVSS vector. No user interaction is indicated by the record, so an attacker can target the FTP service directly.

Exploitation

The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS is very high at 0.82932 (99.655th percentile), indicating a strong likelihood of exploitation activity. No ransomware group associations are documented.

What to do

  • Upgrade Serv-U FTP server to version 9.1.0.0 or later, which is the first version noted as fixing the issue.
  • If immediate upgrade is not possible, restrict network access to the FTP service to trusted hosts and disable or block the TEA decoding functionality if it is not required.
  • Place the FTP service behind a firewall or access control list so that only necessary clients can reach it.
  • Monitor vendor advisories and apply any additional patches or workarounds released for Serv-U.
  • Run the FTP service with least privilege and isolate it from sensitive internal networks where feasible.

Detection

  • Inspect FTP server logs for unusually long hexadecimal strings or malformed TEA-related input that may indicate exploitation attempts.
  • Monitor for crashes or abnormal process termination of the Serv-U FTP service, which can result from stack corruption.
  • Use network monitoring to detect oversized or anomalous FTP command payloads directed at the Serv-U service.
  • Correlate host-based indicators such as unexpected child processes or outbound connections originating from the FTP server process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-4006 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-2532Solarwinds serv-u file server vulnerabilityServ-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands …EPSS 15%10.0CVE-2004-0330Serv-U FTP MDTM time zone buffer overflow allows remote code executionServ-U FTP versions before 5.0.0.4 contain a buffer overflow in the handling of the time zone argument to the MDTM command. A remote authenticated FT…EPSS 85%analysed9.0CVE-2011-4800Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list …EPSS 7.3%9.0CVE-2008-4501Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite …EPSS 11%8.5CVE-2004-2111Serv-U FTP Server site chmod stack buffer overflowServ-U FTP Server before 4.2 has a stack-based buffer overflow in the site chmod command, triggered by a long filename. A remote attacker who can iss…EPSS 87%analysed7.8CVE-2009-1031Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create ar…EPSS 11%7.5CVE-2001-1463Solarwinds serv-u file server vulnerabilityThe remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication…EPSS 3.2%6.1CVE-2021-25179Solarwinds serv-u file server cross-site scripting vulnerabilitySolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2009-4006), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.