← Back to browse · API

CVE-2025-47812

Severity
CRITICAL
CVSS
10.0
EPSS
0.95343
Risk score
58.37
CISA KEV
Yes
PoC
Yes
Published
2025-07-10
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-21009, GHSA-J4XF-75RR-VVRV
Products
Wing FTP Server:Wing FTP Server, Wing FTP Server:Wing FTP Server 0 <7.4.4
Sources
cisa.gov CVE-2025-47812
github 96448f14206f48f578d3a42c|CVE-2025-47812
euvd EUVD-2025-21009

Description

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.

References