CVE‑2025‑47812
Wing FTP
CVE-2025-47812 is a critical vulnerability in Wing FTP Server versions prior to 7.4.4 that allows attackers to execute arbitrary commands on the server without authentication by exploiting improper input validation.
Exploiting this vulnerability can allow an attacker to gain complete control over the affected system. This includes accessing sensitive data, modifying or deleting system resources, and lateral movement.
Impact
Successful exploitation of the Null Wing FTP Server RCE (CVE-2025-47812) vulnerability can lead to:
- Bypassing authentication, even with an anonymous, read-only account.
- Remote code execution as the root user on Linux or the SYSTEM user on Windows.
- Injection and execution of arbitrary Lua code by an attacker.
- Complete control over the affected system, including access to sensitive data, modification or deletion of system resources, and potential for further attacks.
Mitigations
- Upgrade to the latest patched version of Wing FTP.
Rapid Response N-Day Testing
