← Vulnerability feed

Vulnerability record · CVE-2016-4971 · published 30 June 2016

CVE-2016-4971: GNU wget HTTP-to-FTP redirect arbitrary file write

Gnu · Wget

GNU wget before 1.18 follows a server-supplied redirect from HTTP to a crafted FTP resource and writes the retrieved content to an attacker-chosen path on the local filesystem. Because the write is not confined to the intended download target, a malicious or compromised server can overwrite files on the client host. This matters because wget is widely used in scripts and automation, where a single crafted redirect can corrupt or replace files the invoking user can write.

8.8 CVSS 3.1 High EPSS 46% · top 1.2%
8.8CVSS 3.1 base score, v2 4.3
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
26References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityHigh CVSS (8.8) with public exploit code and very high EPSS, though exploitation requires a user or job to fetch an attacker-controlled URL.

What it is

GNU wget before 1.18 follows a server-supplied redirect from HTTP to a crafted FTP resource and writes the retrieved content to an attacker-chosen path on the local filesystem. Because the write is not confined to the intended download target, a malicious or compromised server can overwrite files on the client host. This matters because wget is widely used in scripts and automation, where a single crafted redirect can corrupt or replace files the invoking user can write.

Impact

An attacker controlling the server response gains the ability to write arbitrary files with the privileges of the wget process, which can lead to code execution or configuration tampering depending on what is overwritten. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network when a user or automated job runs wget against an attacker-influenced URL that redirects from HTTP to FTP; no authentication is required, but user interaction (initiating the download) is needed per the CVSS vector UI:R.

Exploitation

Not listed in CISA KEV, but public exploit code exists (Exploit-DB 40064, Packet Storm, Red Hat Bugzilla tagged Exploit) and EPSS is 0.4606 (98.75th percentile), indicating elevated likelihood of exploitation.

What to do

  • Upgrade wget to 1.18 or later; the vendor patch commit is referenced in the advisory.
  • Apply distribution updates for wget on Ubuntu (USN-3012-1), Gentoo (GLSA 201610-11) and other affected platforms.
  • Avoid running wget against untrusted or redirecting URLs, and restrict outbound HTTP/FTP where feasible.
  • Run wget with least privilege and in a sandbox or container so arbitrary writes cannot reach sensitive paths.

Detection

  • Monitor wget invocations that follow HTTP-to-FTP redirects, especially in cron jobs and CI pipelines.
  • Alert on unexpected file creation or modification in directories writable by the wget process.
  • Review outbound FTP connections from hosts that normally only fetch over HTTP.
  • Check installed wget versions against the 1.18 fixed release across managed endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://git.savannah.gnu.org/cgit/wget.git/commit/?id=e996e322ffd42aaa051602da182d03178d0f13e1 PatchVendor Advisory
http://lists.gnu.org/archive/html/info-gnu/2016-06/msg00004.html Mailing ListPatchVendor Advisory
http://lists.opensuse.org/opensuse-updates/2016-08/msg00043.html Broken Link
http://packetstormsecurity.com/files/162395/GNU-wget-Arbitrary-File-Upload-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://rhn.redhat.com/errata/RHSA-2016-2587.html Broken Link
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html Third Party Advisory
http://www.securityfocus.com/bid/91530 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036133 Third Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-3012-1 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1343666 ExploitIssue TrackingPatchThird Party Advisory
https://security.gentoo.org/glsa/201610-11 Third Party Advisory
https://security.paloaltonetworks.com/CVE-2016-4971 Third Party Advisory
https://www.exploit-db.com/exploits/40064/ ExploitThird Party AdvisoryVDB Entry
http://git.savannah.gnu.org/cgit/wget.git/commit/?id=e996e322ffd42aaa051602da182d03178d0f13e1 PatchVendor Advisory
http://lists.gnu.org/archive/html/info-gnu/2016-06/msg00004.html Mailing ListPatchVendor Advisory
http://lists.opensuse.org/opensuse-updates/2016-08/msg00043.html Broken Link
http://packetstormsecurity.com/files/162395/GNU-wget-Arbitrary-File-Upload-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://rhn.redhat.com/errata/RHSA-2016-2587.html Broken Link
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html Third Party Advisory
http://www.securityfocus.com/bid/91530 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036133 Third Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-3012-1 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1343666 ExploitIssue TrackingPatchThird Party Advisory
https://security.gentoo.org/glsa/201610-11 Third Party Advisory
https://security.paloaltonetworks.com/CVE-2016-4971 Third Party Advisory
https://www.exploit-db.com/exploits/40064/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2016-4971 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-14871Oracle Solaris PAM out-of-bounds write allows remote unauthenticated takeoverOracle Solaris 10 and 11 contain an out-of-bounds write (CWE-787) in the Pluggable Authentication Module component, reachable over the network withou…KEVEPSS 80%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2019-16928Exim heap buffer overflow in string_vformat via long EHLO commandExim 4.92 through 4.92.2 contains a heap-based buffer overflow in string_vformat in string.c triggered by a long EHLO command, allowing remote code e…KEVEPSS 42%analysed9.8CVE-2019-10149Exim MTA improper recipient validation leads to remote command executionExim versions 4.87 through 4.91 fail to properly validate recipient addresses in the deliver_message() function in /src/deliver.c, allowing command i…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2016-4971), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.