S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jul 1, 2025

CVE-2025-47812 Scanner

CVE-2025-47812 Scanner - Remote Code Execution (RCE) vulnerability in Wing FTP Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-47812
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Wing FTP Serverby wftpserver
AFFECTED< 7.4.4SAFE ✓≥ 7.4.4
Updated Aug 22, 2026View on NVD →
Detail

Wing FTP Server is an efficient and secure FTP server solution used by a variety of organizations for transferring files over networks. It provides features such as web-based interface management, encrypted file transfers, and event management. Typically used by IT administrators and professionals, Wing FTP Server can support multiple file transfer protocols like FTP, HTTP, and SFTP. It is favored in sectors where secure and reliable file transfers are essential, such as finance, healthcare, and tech industries. Wing FTP Server's ease of use and robust feature set make it a popular choice for businesses wanting to manage their data transfers securely.

This vulnerability involves a Remote Code Execution (RCE) flaw in Wing FTP Server, specifically affecting versions up to 7.4.3. The vulnerability arises due to improper handling of NULL bytes in the 'username' parameter during login. This improper handling allows for Lua code injection within session files. These injected session files can subsequently be executed when interacting with authenticated endpoints, allowing arbitrary command execution. The vulnerability is critical as it allows for execution with elevated privileges, compromising the server's integrity.

The RCE vulnerability in Wing FTP Server exploits the login process by injecting malicious Lua scripts. The vulnerability uses improper NULL byte handling to insert scripts into session files, which are later executed. Attackers take advantage of endpoints like /dir.html to trigger these malicious scripts. The inappropriate handling during login results in unauthorized commands running with elevated server permissions. These exploits are possible particularly when anonymous login is enabled in the server settings. The technical basis of this vulnerability requires careful consideration of both username parameter handling and session file security.

Exploiting this vulnerability can have severe consequences, including unauthorized access to sensitive data and potential control over the server. Attackers could potentially execute any command on the server, leading to data theft or service disruption. Additionally, the compromised server could be used as a launch pad for further attacks within the organization. The elevated privileges mean attackers can have a significant impact, potentially altering, deleting, or injecting harmful data. The critical nature of this vulnerability highlights the necessity for immediate remediation to maintain server integrity and security.

REFERENCES

Solution Advice
  • Upgrade Wing FTP Server to version 7.4.4 or later to mitigate this vulnerability.
  • Ensure that anonymous login is disabled if not needed, and carefully review login configurations.
  • Employ intrusion detection systems to monitor unusual activities.
  • Regularly audit user access privileges and session file handling practices.
  • Implement network monitoring and alerting for unusual traffic patterns related to the FTP server.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.