📦

serv-u

Vendor: rhinosoft

Actively Exploited 3 CISA KEV List
PoC / Exploits 7 Code Available
Total RCEs 2 Remote Access
Total CVEs 225 Total Indexed
Avg. EPSS 9.49% Exploit Prob.
Latest CVE CVE-2025-40541 Feb 24

Security Vulnerability Index

Page 5 / 23
7.5 CVSS
CVE-2000-1033
Exploit Found

Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users.

EPSS: 3.79%
5.0 CVSS

The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.

EPSS: 0.76%