CVE-2025-47813 – Medium‑Severity Information Disclosure in Wing FTP Server
CVE-2025-47813 is a Medium severity information‑disclosure flaw in Wing FTP Server that reveals the full installation path via a crafted UID cookie. The bug affects all versions prior to 7.4.4.
Key takeaways
- CVE-2025-47813 – Medium (CVSS 4.3) info‑leak in Wing FTP Server < 7.4.4.
- Leaks absolute server file system path through the
loginok.htmlendpoint when the UID cookie contains an over‑long value.- Actively exploited in the wild; added to CISA KEV on 2026‑03‑16.
- Remediation: upgrade to Wing FTP Server 7.4.4 or later; block external FTP access; sanitize cookie handling.
- Immediate actions: inventory FTP servers, apply the patch, monitor for suspicious UID cookie values, and isolate FTP services.
Overview
- Discovery & Disclosure: The vulnerability was publicly disclosed in early 2025, but active exploitation only surfaced after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed it in the Known Exploited Vulnerabilities (KEV) catalog on 2026‑03‑16.
- Threat Activity: According to open‑source signal tracking, active exploitation reports jumped from 8 on 2026‑03‑16 to 23 on 2026‑03‑17, then tapered off but remained present through 2026‑03‑20. For a live timeline of indicators, see the CVE page.
- Why it matters: Although the CVSS score is Medium, the disclosed file‑system path gives attackers a reliable foothold for further attacks, especially when chained with the related RCE bug CVE-2025-47812 that targets the same product.
Technical Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2025-47813 |
| Severity | Medium (CVSS 4.3) |
| CVSS Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| CWE | CWE-209 – Generation of Error Message Containing Sensitive Information |
| Vendor | wftpserver |
| Product | Wing FTP Server |
| Affected Versions | All releases before 7.4.4 |
| Fixed In | 7.4.4 |
| CISA KEV | Yes (added 2026‑03‑16) |
The flaw resides in the loginok.html page. When a client sends an UID cookie with a value longer than expected, the server concatenates the value into an error message that includes the absolute path of the Wing FTP installation directory (e.g., C:\Program Files\Wing FTP Server\). This path is then reflected back to the client, providing a clear view of the server’s file‑system layout.
The vulnerability is classified under CWE‑209 because the error message unintentionally discloses sensitive internal information. The CVSS vector reflects that the attack is network‑remote, requires low attack complexity, and can be performed by a low‑privileged attacker without user interaction.
Severity & Impact
- Confidentiality: The disclosed path reveals internal directory structure, which can aid attackers in locating configuration files, credential stores, or other sensitive assets.
- Integrity & Availability: No direct impact, but the information can be leveraged to craft more potent attacks (e.g., path‑traversal, RCE).
- Risk Amplification: When paired with CVE‑2025‑47812 (a remote code execution flaw in the same product), the path disclosure dramatically reduces the attack surface for a full compromise.
Affected Products
- Vendor: wftpserver
- Product: Wing FTP Server (all versions prior to 7.4.4)
For the complete list of affected versions and CPE identifiers, see the CVE page.
Actionable Insights – What to Do Now
- Identify every instance of Wing FTP Server in your environment. Use inventory tools or search for the
wftpserverservice/process. - Upgrade all vulnerable installations to Wing FTP Server 7.4.4 or later. The patch removes the over‑long UID handling and disables the path disclosure.
- Block inbound FTP (port 21) from untrusted networks until the patch is applied. Prefer VPN or SFTP alternatives.
- Monitor web server logs for requests to
loginok.htmlthat contain unusually longUIDcookie values (e.g., > 256 bytes). Flag any such events for investigation. - Sanitize cookie handling: enforce a maximum length on the UID cookie at the application layer or via a reverse‑proxy/WAF rule.
- Segment the FTP service on a dedicated VLAN or subnet to limit lateral movement if the server is compromised.
- Audit related configurations (e.g., stored credentials, configuration files) for exposure once the path is known.
Remediation & Mitigation
- Apply the official patch (Wing FTP Server 7.4.4) from the vendor.
- Restart the FTP service after upgrading to ensure the new binaries are loaded.
- Validate the fix by sending a crafted UID cookie and confirming that the response no longer contains the installation path.
- Implement network controls (firewall rules, IP allow‑lists) to restrict FTP access to trusted hosts only.
- Deploy a WAF rule to truncate or reject UID cookies exceeding the expected length (e.g.,
if (cookie.UID.length > 128) { block }).
Bottom Line
CVE-2025-47813 is a Medium‑severity information‑disclosure flaw in Wing FTP Server that has been actively exploited and is now listed in the CISA KEV catalog. The vulnerability discloses the server’s installation path, enabling attackers to accelerate subsequent exploits such as the related RCE bug (CVE‑2025‑47812). Immediate remediation—upgrading to version 7.4.4 and tightening cookie handling—combined with vigilant monitoring, will neutralize the current threat.
References
- https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-47813.txt
- https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/
- https://www.wftpserver.com
#CVE #CVE202547813 #WingFTPServer #CISAKEV #InfoLeak #Medium #Security #Patch #Remediation
