S4E just found a critical-severity finding from cve-2024-42009 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Network Vulnerabilities·Updated Oct 7, 2025

CVE-2021-40524 Scanner

CVE-2021-40524 Scanner - Arbitrary File Upload vulnerability in Pure-FTPd

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
3.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-40524
7.5
CVSS

In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are affected.)

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Pure-FTPd is an FTP server used globally by various organizations for secure file transfers. It is valued for its simplicity, security features, and compliance with FTP standards, serving both small businesses and large enterprises. Pure-FTPd supports TLS and SSL protocols, enhancing the security of transferred data. Its popularity is due to its open-source nature and the ease of customization for diverse user needs. Widely installed on Linux and UNIX systems, it helps manage website content and share large files efficiently. However, like all software, it can harbor vulnerabilities that could compromise system security.

The Arbitrary File Upload vulnerability in Pure-FTPd allows unauthorized users to upload files without size restrictions, bypassing the intended max_filesize quota. This oversight can lead to an unbounded file upload, which may cause server performance to degrade or completely hang due to resource exhaustion. The issue predominantly affects versions 1.0.23 through 1.0.49, presenting a significant risk to systems that rely on these versions for file transfer operations. Once exploited, attackers can potentially upload malicious payloads, hindering the server's functionality. Administrators should urgently address this vulnerability to prevent exploitation.

This vulnerability primarily stems from the maximum filesize quota enforcement logic in Pure-FTPd, which fails to adequately restrict upload sizes. The endpoint affected typically handles file management requests, allowing users to transfer files onto the server. If exploited, an attacker can upload arbitrary files by invoking the relevant FTP commands to the affected endpoints within versions 1.0.23 to 1.0.49. The vulnerable parameter could include file size or upload directives commonly mismanaged due to the flaw. During a successful attack, a malicious file gets stored, compromising system integrity.

Exploiting this vulnerability can result in several adverse effects, including denial of service when the server resources are exhausted. It may also lead to unauthorized storage of sensitive or malicious files, which can be executed remotely to carry out further attacks. This can compromise data integrity and confidentiality, causing severe disruptions in normal server operations. Organizations may encounter data breaches, loss of customer trust, and legal implications if sensitive data is compromised due to the vulnerability. Therefore, timely mitigation is vital to limit potential damage and secure server environments.

REFERENCES

Solution Advice
  • Update Pure-FTPd to the latest version where this flaw is resolved.
  • Implement strict file upload policies to prevent unauthorized or unverified file types.
  • Use additional security layers such as firewalls or intrusion detection systems to monitor upload activities.
  • Limit file upload permissions to trusted users and verify file integrity post-upload.
  • Regularly audit and monitor FTP server logs to identify any unusual activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-40524 Scanner - Arbitrary File Upload vulnerability in Pure-FTPd | S4E