CISA Adds ProFTPD CVE-2015-3306 to KEV as Flax Typhoon Exploits Five
CISA set an October 11 federal patch deadline after Flax Typhoon exploited CVE-2015-3306, a CVSS 10.0 ProFTPD flaw, plus four other bugs in its KEV batch.

Executive Summary
CISA added CVE-2015-3306, a CVSS 10.0 improper access control flaw in the ProFTPD FTP server, to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, alongside four other vulnerabilities linked to the China-nexus threat actor tracked as Flax Typhoon. The agency set an October 11 remediation deadline for U.S. federal civilian agencies, giving administrators roughly 24 hours from the catalog update to patch or mitigate.
The ProFTPD bug is the standout entry: it is more than a decade old, carries the maximum base score, and remains reachable on internet-exposed FTP services that were never upgraded past the affected 1.3.5 release. Defenders running ProFTPD should treat this as an active-exploitation event, not a historical curiosity — the KEV listing is the strongest public signal that the flaw is being used in the wild right now.
Technical Analysis
CVE-2015-3306 affects the mod_copy module in ProFTPD 1.3.5. The module exposes the SITE CPFR (copy from) and SITE CPTO (copy to) commands, which are intended to let authenticated users duplicate files server-side. The flaw is that these commands are processed before authentication is enforced, so an unauthenticated client can instruct the server to copy an arbitrary file from one path to another.
The classic exploitation pattern is to copy a file the attacker already controls — typically a PHP or JSP payload uploaded through a separate channel, or content placed in a world-writable directory — into a web-accessible location under the FTP root. Because ProFTPD is frequently deployed on the same host as an Apache, nginx, or Tomcat instance, the copied file becomes a webshell reachable over HTTP. That turns a file-transfer misconfiguration into remote code execution without any credential requirement.
The CVSS 10.0 score reflects that combination: network-reachable, no authentication, no user interaction, and full confidentiality, integrity, and availability impact. CISA's KEV entry does not publish the specific exploitation chain Flax Typhoon used, and the agency has not released the IP addresses, hashes, or webshell filenames associated with the campaign. The Hacker News report attributes the five-flaw KEV batch to Flax Typhoon activity but does not enumerate the other four CVEs in the excerpt available to this article; readers should consult the CISA KEV catalog directly for the full batch.
Flax Typhoon is a China-linked intrusion set that U.S. authorities have previously tied to exploitation of internet-facing edge devices and VPN appliances. Its inclusion in this KEV batch is consistent with that pattern: the group favors long-lived, unauthenticated flaws on perimeter services over user-driven phishing.
Mitigations & Recommendations
ProFTPD administrators should verify their running version and confirm whether mod_copy is loaded. If the module is not required, disabling it removes the attack surface entirely. If it is required, upgrading past the affected 1.3.5 build is the correct fix — the flaw was patched upstream years ago, so the population still at risk is almost certainly running an unmaintained or frozen build.
Because the exploitation path depends on placing a file that can later be copied into a web-served directory, defenders should also audit FTP roots for unexpected file writes, review web server access logs for requests to files whose names do not match any deployed application, and check for outbound connections from FTP hosts to unfamiliar destinations. Federal agencies covered by the binding operational directive have until October 11 to remediate; private-sector operators running ProFTPD on internet-facing hosts should treat the same deadline as their own.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.

