Port 21: File Transfer Protocol (control connection)
Port 21 carries the FTP control connection, where clients send commands such as USER, PASS, PORT, and PASV and receive replies. File contents move over a separate data connection on port 20 in active mode or on a dynamic port in passive mode. FTP is defined in RFC 959, and RFC 4217 adds TLS protection through the AUTH TLS command.
Port Details
Security Exposure
Standard FTP sends usernames, passwords, and data in cleartext, according to RFC 2577 and UK government guidance. Internet-facing FTP servers attract password guessing; MITRE ATT&CK lists FTP on 21/TCP among commonly targeted services. Anonymous login and misconfigured write permissions can let outsiders read, upload, or modify files.
Hardening
- +Disable FTP and remove inbound rules for port 21 if file transfer over FTP is not required.
- +Move to SFTP, or require FTPS through AUTH TLS (RFC 4217) so credentials and data are encrypted.
- +Disable anonymous login unless a public download area is intended, and do not allow anonymous uploads.
- +Limit failed password attempts per connection and delay replies to invalid PASS commands, as RFC 2577 suggests.
- +Restrict access to port 21 to trusted source addresses at the firewall.
Monitoring
Review FTP server logs for repeated 530 login failures, anonymous logins, and uploads to unexpected directories. RFC 2577 notes that an intruder can open multiple parallel control connections to get around per-connection password attempt limits.
FTP Vulnerabilities
4 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2015-3306 | ProFTPD Improper Access Control Vulnerability | - | 10.0 | 96.8% | KEV | 2015-05-18 |
| CVE-2025-47813 | Wing FTP Server Information Disclosure Vulnerability | wftpserver | 4.3 | 63.1% | KEV | 2025-07-10 |
| CVE-2025-47812 | Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability | wftpserver | 10.0 | 93.2% | KEV | 2025-07-10 |
| CVE-2021-35211 | Serv-U Remote Memory Escape Vulnerability | SolarWinds | 9.0 | 91.2% | KEV | 2021-07-14 |
Tools for Auditing and Monitoring FTP
Hydra
Open SourceParallelized network login auditing tool that tests dozens of remote authentication protocols including SSH, SMB, RDP, HTTP, and database services.
OpenCanary
Open SourceOpen source multi-protocol daemon honeypot from the Thinkst Canary project.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Frequently Asked Questions
Is FTP on port 21 encrypted?→
No. Standard FTP sends commands, passwords, and data unencrypted (RFC 2577). Encryption requires FTPS, which adds TLS to FTP (RFC 4217), or a different protocol such as SFTP.
Should port 21 be open to the internet?→
UK Government Cyber Unit guidance recommends disabling FTP when it is not needed, removing port 21 forwarding rules, and switching to SFTP or FTPS. If FTP must remain, restrict it to trusted IP addresses.
Is SFTP the same as FTP on port 21?→
No. SFTP is the SSH File Transfer Protocol and runs inside SSH, normally on port 22. FTPS is FTP with TLS added.
Which vulnerabilities affect the service on port 21?→
This database lists 4 CVEs related to FTP, 4 of them confirmed as exploited by CISA. Examples: CVE-2015-3306, CVE-2025-47813, CVE-2025-47812, CVE-2021-35211.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 21 is not guaranteed to be FTP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).