Vulnerability record · CVE-2016-4971 · published 30 June 2016
CVE-2016-4971: GNU wget HTTP-to-FTP redirect arbitrary file write
Gnu · Wget
GNU wget before 1.18 follows a server-supplied redirect from HTTP to a crafted FTP resource and writes the retrieved content to an attacker-chosen path on the local filesystem. Because the write is not confined to the intended download target, a malicious or compromised server can overwrite files on the client host. This matters because wget is widely used in scripts and automation, where a single crafted redirect can corrupt or replace files the invoking user can write.
Description
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (8.8) with public exploit code and very high EPSS, though exploitation requires a user or job to fetch an attacker-controlled URL.
What it is
GNU wget before 1.18 follows a server-supplied redirect from HTTP to a crafted FTP resource and writes the retrieved content to an attacker-chosen path on the local filesystem. Because the write is not confined to the intended download target, a malicious or compromised server can overwrite files on the client host. This matters because wget is widely used in scripts and automation, where a single crafted redirect can corrupt or replace files the invoking user can write.
Impact
An attacker controlling the server response gains the ability to write arbitrary files with the privileges of the wget process, which can lead to code execution or configuration tampering depending on what is overwritten. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network when a user or automated job runs wget against an attacker-influenced URL that redirects from HTTP to FTP; no authentication is required, but user interaction (initiating the download) is needed per the CVSS vector UI:R.
Exploitation
Not listed in CISA KEV, but public exploit code exists (Exploit-DB 40064, Packet Storm, Red Hat Bugzilla tagged Exploit) and EPSS is 0.4606 (98.75th percentile), indicating elevated likelihood of exploitation.
What to do
- Upgrade wget to 1.18 or later; the vendor patch commit is referenced in the advisory.
- Apply distribution updates for wget on Ubuntu (USN-3012-1), Gentoo (GLSA 201610-11) and other affected platforms.
- Avoid running wget against untrusted or redirecting URLs, and restrict outbound HTTP/FTP where feasible.
- Run wget with least privilege and in a sandbox or container so arbitrary writes cannot reach sensitive paths.
Detection
- Monitor wget invocations that follow HTTP-to-FTP redirects, especially in cron jobs and CI pipelines.
- Alert on unexpected file creation or modification in directories writable by the wget process.
- Review outbound FTP connections from hosts that normally only fetch over HTTP.
- Check installed wget versions against the 1.18 fixed release across managed endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-4971 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-4971), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.