CVE-2025-47812
CRITICAL CISA KEVDescription
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| wftpserver | wing_ftp_server |
References
Exploits
Other References
Frequently Asked Questions
What is CVE-2025-47812? +
How severe is CVE-2025-47812? +
What products are affected by CVE-2025-47812? +
How do I check if I'm vulnerable to CVE-2025-47812? +
Related Vulnerabilities
A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By …
The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up …
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support …
Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, …
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when …
An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted …