CVE-2020-37032Disclosure(wftpserver / wing_ftp_server)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage the console to send POST requests with malicious commands that trigger operating system execution through the os.execute() function.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wing_ftp_server

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-01-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
wing_ftp_server

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-30: 1Mentions · 2026-01-31: 1Technical Details · 2026-01-30: 1Technical Details · 2026-01-31: 101-3001-31
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2020-37032: HIGH] Wing FTP Server 6.3.8 is vulnerable to remote code execution via its Lua-based web console. Authenticated users can exploit the flaw to execute system commands.#cve,CVE-2020-37032,#cybersecurity https://cvefind.com/CVE-2020-37032

    Post summary

    Wing FTP Server 6.3.8 allows authenticated users to exploit a Lua-based web console for remote code execution, enabling arbitrary system command execution.

    00000185
    584 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2020-37032 Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attacker… https://www.cve.org/CVERecord?id=CVE-2020-37032

    Post summary

    The tweet announces that Wing FTP Server 6.3.8 contains a remote code execution vulnerability via its Lua-based web console, enabling authenticated users to run system commands, with no PoC, exploit, patch, or active exploitation mentioned.

    00000196
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwftpserverwing_ftp_server6.3.8--

Explore more