Eweek is reporting that a security vendor is questioning whether the IOS FTP Server vulnerability Cisco reported last week could be an intentionally planted backdoor, rather than one that was inadvertently programmed into IOS.
According to eWeek:
Chris Eng, director of security services at Veracode, is suggesting that possibility given that a remote attacker would need one of the flaws—improper authorization checking in IOS FTP—in order to exploit the second flaw—an IOS reload when transferring files via FTP.
In essence, an attacker can bypass authentication and avoid giving credentials because of the first flaw. The attacker then has to overwrite the critical startup configuration file, then has to cause the router itself to reboot in order to execute the rewritten configuration file.




