CVE-2010-2620
Open-ftpd < 1.2 - Authentication Bypass
Title source: ruleDescription
Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or other commands without performing the required login steps first.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Wireghoul · pythonremotewindows
https://www.exploit-db.com/exploits/27401
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/27556
exploitdb
WORKING POC
VERIFIED
by Serge Gorbunov · pythonremotewindows
https://www.exploit-db.com/exploits/13932
metasploit
WORKING POC
EXCELLENT
by Serge Gorbunov, bcoles · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/ftp/open_ftpd_wbem.rb
Scores
EPSS
0.5567
EPSS Percentile
98.0%
Classification
CWE
CWE-287
Status
draft
Affected Products (2)
open-ftpd/open-ftpd
< 1.2
open-ftpd/open-ftpd
Timeline
Published
Jul 02, 2010
Tracked Since
Feb 18, 2026