Vulnerability record · CVE-2009-4006 · published 20 November 2009
CVE-2009-4006: Serv-U FTP Server TEA Decoding Stack Buffer Overflow
Solarwinds · Serv U File Server
RhinoSoft Serv-U FTP server versions before 9.1.0.0 contain a stack-based buffer overflow in the TEA decoding algorithm. A remote attacker can trigger the overflow by sending a long hexadecimal string, which may corrupt the stack and allow arbitrary code execution. The flaw is remotely reachable and carries a maximum CVSS v2 base score of 10.0.
Description
Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityThe CVSS v2 score is 10.0 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, and EPSS is extremely high at 0.82932.
What it is
RhinoSoft Serv-U FTP server versions before 9.1.0.0 contain a stack-based buffer overflow in the TEA decoding algorithm. A remote attacker can trigger the overflow by sending a long hexadecimal string, which may corrupt the stack and allow arbitrary code execution. The flaw is remotely reachable and carries a maximum CVSS v2 base score of 10.0.
Impact
Successful exploitation can allow a remote attacker to execute arbitrary code in the context of the Serv-U FTP service. That could lead to full compromise of the FTP server host, including data theft, service disruption, or use as a pivot point.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity and no authentication required (Au:N), based on the CVSS vector. No user interaction is indicated by the record, so an attacker can target the FTP service directly.
Exploitation
The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS is very high at 0.82932 (99.655th percentile), indicating a strong likelihood of exploitation activity. No ransomware group associations are documented.
What to do
- Upgrade Serv-U FTP server to version 9.1.0.0 or later, which is the first version noted as fixing the issue.
- If immediate upgrade is not possible, restrict network access to the FTP service to trusted hosts and disable or block the TEA decoding functionality if it is not required.
- Place the FTP service behind a firewall or access control list so that only necessary clients can reach it.
- Monitor vendor advisories and apply any additional patches or workarounds released for Serv-U.
- Run the FTP service with least privilege and isolate it from sensitive internal networks where feasible.
Detection
- Inspect FTP server logs for unusually long hexadecimal strings or malformed TEA-related input that may indicate exploitation attempts.
- Monitor for crashes or abnormal process termination of the Serv-U FTP service, which can result from stack corruption.
- Use network monitoring to detect oversized or anomalous FTP command payloads directed at the Serv-U service.
- Correlate host-based indicators such as unexpected child processes or outbound connections originating from the FTP server process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-4006 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-4006), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.