Skip to main content

Port Details

Port
21
Transport
TCP
Service
FTP
IANA service name
ftp
Range
System port (0-1023)
Related ports

Security Exposure

Standard FTP sends usernames, passwords, and data in cleartext, according to RFC 2577 and UK government guidance. Internet-facing FTP servers attract password guessing; MITRE ATT&CK lists FTP on 21/TCP among commonly targeted services. Anonymous login and misconfigured write permissions can let outsiders read, upload, or modify files.

Hardening

  • +Disable FTP and remove inbound rules for port 21 if file transfer over FTP is not required.
  • +Move to SFTP, or require FTPS through AUTH TLS (RFC 4217) so credentials and data are encrypted.
  • +Disable anonymous login unless a public download area is intended, and do not allow anonymous uploads.
  • +Limit failed password attempts per connection and delay replies to invalid PASS commands, as RFC 2577 suggests.
  • +Restrict access to port 21 to trusted source addresses at the firewall.

Monitoring

Review FTP server logs for repeated 530 login failures, anonymous logins, and uploads to unexpected directories. RFC 2577 notes that an intruder can open multiple parallel control connections to get around per-connection password attempt limits.

FTP Vulnerabilities

4 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2015-3306
ProFTPD Improper Access Control Vulnerability
-10.096.8%KEV2015-05-18
CVE-2025-47813
Wing FTP Server Information Disclosure Vulnerability
wftpserver4.363.1%KEV2025-07-10
CVE-2025-47812
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability
wftpserver10.093.2%KEV2025-07-10
CVE-2021-35211
Serv-U Remote Memory Escape Vulnerability
SolarWinds9.091.2%KEV2021-07-14

Tools for Auditing and Monitoring FTP

Hydra

Open Source
Password Cracking

Parallelized network login auditing tool that tests dozens of remote authentication protocols including SSH, SMB, RDP, HTTP, and database services.

LicenseAGPL-3.0-only with OpenSSL exception
PlatformLinux, macOS, Windows, BSD, Solaris

OpenCanary

Open Source
Honeypot & Deception Tools

Open source multi-protocol daemon honeypot from the Thinkst Canary project.

LicenseBSD-3-Clause
PlatformLinux, macOS

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

Is FTP on port 21 encrypted?→

No. Standard FTP sends commands, passwords, and data unencrypted (RFC 2577). Encryption requires FTPS, which adds TLS to FTP (RFC 4217), or a different protocol such as SFTP.

Should port 21 be open to the internet?→

UK Government Cyber Unit guidance recommends disabling FTP when it is not needed, removing port 21 forwarding rules, and switching to SFTP or FTPS. If FTP must remain, restrict it to trusted IP addresses.

Is SFTP the same as FTP on port 21?→

No. SFTP is the SSH File Transfer Protocol and runs inside SSH, normally on port 22. FTPS is FTP with TLS added.

Which vulnerabilities affect the service on port 21?→

This database lists 4 CVEs related to FTP, 4 of them confirmed as exploited by CISA. Examples: CVE-2015-3306, CVE-2025-47813, CVE-2025-47812, CVE-2021-35211.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 21 is not guaranteed to be FTP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).