CVE-2025-47812Active Exploitation(wftpserver / wing_ftp_server)

MEDIUMCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch wftpserver wing_ftp_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-08-04. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-158

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wing_ftp_server

Threat summary

  • Active exploitation appears in 7 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 6 observed days

What's happening

  • Active exploitation reported across 7 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Peaked 3d ago at 4 mentions (2026-03-17); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
wing_ftp_server

Deep dive

Activity timeline10 mentions / 6d
01234Mentions · 2026-02-04: 1Mentions · 2026-02-16: 1Mentions · 2026-03-17: 4Mentions · 2026-03-25: 2Mentions · 2026-04-03: 1Mentions · 2026-06-29: 1PoC Mentioned / Linked · 2026-02-16: 1PoC Mentioned / Linked · 2026-03-17: 1Active Exploitation · 2026-02-04: 1Active Exploitation · 2026-03-17: 4Active Exploitation · 2026-03-25: 2Patch / Workaround · 2026-03-17: 4Patch / Workaround · 2026-04-03: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-16: 1Technical Details · 2026-03-17: 2Technical Details · 2026-03-25: 2Technical Details · 2026-04-03: 1Technical Details · 2026-06-29: 102-0402-1603-1703-2504-0306-29
Signal classification4 categories
Active Exploitation
770.0%
PoC
110.0%
Patch
110.0%
Disclosure
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-041
Active Exploitation1
2026-02-161
PoC1
2026-03-174
Active Exploitation4
2026-03-252
Active Exploitation2
2026-04-031
Patch1
2026-06-291
Disclosure1
Full discourse10 posts
  • Criminal IP@CriminalIP_US
    Active Exploitation

    📡Wing FTP Vulnerability → RCE Attack Chain Risk​ CVE-2025-47813 is actively exploited and added to CISA KEV.​ On its own, it exposes server paths, but the real risk appears when chained.​ ​ Combined with CVE-2025-47812 (RCE):​ Exposure → Path Leak → RCE → System Compromise​ Criminal IP analysis shows:​ ✔️ Multiple Wing FTP services internet-exposed​ ✔️ status_code:200 interfaces directly accessible​ ✔️ Some management pages publicly reachable​ Even “medium” vulnerabilities can escalate when exposure exists.​ ​ 🔎 Full analysis​ https://www.criminalip.io/knowledge-hub/blog/33366​ ​ #ThreatIntelligence #CyberSecurity #RCE #ASM

    Post summary

    CVE‑2025‑47813 is actively being exploited and reported by CISA KEV, with a chainable RCE via CVE‑2025‑47812, yet no patch or PoC is disclosed.

    00020261
    4.8K followersView on X
  • Criminal IP Japan@CriminalIP_JP
    Active Exploitation

    📁Wing FTP情報漏えい脆弱性(CVE-2025-47813)​ 最近、Wing FTP Serverで発見された情報漏えい脆弱性が実際の攻撃に悪用され、KEVに追加されました。この脆弱性は、長いUIDクッキー値の処理過程で​サーバーのローカルインストールパスが露出する問題です。​ ​ 💡 Criminal IP 観点の分析​ ▪ インターネット上に露出したWing FTPサービスを多数確認​ ▪ Webインターフェースへ直接アクセス可能な環境の存在​ ▪ バナーやレスポンス情報からバージョン・構成の推定が可能​ 特に本脆弱性は単体よりも、RCE脆弱性(CVE-2025-47812)と組み合わせることでリスクが増大します。パス情報取得 → 脆弱バージョン特定 → コード実行といった実際の攻撃チェーンにつながる可能性があります。​ 🔎 詳細分析はこちら​ https://www.criminalip.io/ja/knowledge-hub/blog/8309​ #サイバーセキュリティ #脆弱性 #脅威インテリジェンス

    Post summary

    CVE‑2025‑47813 in Wing FTP Server has been actively exploited, exposing local install paths through UID cookie processing and potentially enabling code execution when combined with CVE‑2025‑47812; no PoC, exploit code, or patch information is provided.

    00001364
    1.4K followersView on X
  • Techzine@techzine
    Active Exploitation

    CISA warns of active exploitation of Wing FTP Server vulnerabilities. CVE-2025-47813 and CVE-2025-47812 have been patched in version 7.4.4. http://dlvr.it/TRXRtf #Security #CISA #CVE202547812 #CVE202547813 #FTP - Follow for more

    Post summary

    CISA reports that CVE-2025-47813 and CVE-2025-47812 are actively being exploited, while the vendor has issued a patch in version 7.4.4.

    00010100
    9.0K followersView on X
  • sckull@sckull_
    Disclosure

    HackTheBox - WingData 💥 RCE en Wing FTP Server (CVE-2025-47812) para acceso inicial 🔑 Credenciales para SSH de Wing FTP Server 🚀 Abuso de tarfile (CVE-2025-4517) para escalar privilegios https://sckull.github.io/posts/wingdata/

    Post summary

    The post discloses a Remote Code Execution vulnerability in Wing FTP Server (CVE-2025-47812) and a privileged escalation via tarfile misuse (CVE-2025-4517), providing initial access credentials and linking to a post for further details.

    0000042
    177 followersView on X
  • Vladimir Cageyv Samoylov@cageyvdev
    Patch

    🚨 AI surge = cyber surge for tech leaders! Patch Wing FTP NOW (CVE-2025-47812 RCE CVSS 10). Stryker hack disrupts healthcare. Banks: 1300% AI fraud jump. Nvidia $20B Groq deal, YC favors grit over Ivy. Innovate & defend! #AI #Cyber

    Post summary

    The post announces the Wing FTP RCE (CVE‑2025‑47812) with a high severity score and urges immediate patching, without mentioning PoC, exploit tools, or active exploitation.

    00000258
    26 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    🎤 RadioCSIRT Ep.600 – Mardi 17 mars 2026 Quatre sujets. Veille cyber quotidienne. 🔴 Wing FTP Server – CVE-2025-47813 ajoutée au catalogue KEV de la CISA. Exploitation active confirmée. Information Disclosure exploitable en chaîne avec CVE-2025-47812, une RCE critique. Correctif disponible depuis mai 2025 en version 7.4.4. Délai de remédiation de deux semaines imposé aux agences fédérales américaines sous BOD 22-01. 🔴 CERT-FR – Quatre avis publiés le 16 mars 2026. CVE-2026-3909 dans Google Chrome et CVE-2026-3910 dans Microsoft Edge confirmées comme activement exploitées. Trente et une CVE documentées sur Edge versions antérieures à 146.0.3856.59. OpenSSL affecté par CVE-2026-2673 sur les branches 3.5.x et 3.6.x. Six CVE additionnelles sur des composants Azure Linux : coredns, giflib, golang, azurelinux-image-tools. 🔴 Starcloud – Demande déposée auprès de la FCC pour le déploiement d'une mégaconstellation de 88 000 satellites en orbite héliosynchrone. Infrastructure de data centers orbitaux visant 5 gigawatts de puissance de calcul. Soutenue par NVIDIA. Proof-of-concept opérationnel avec un GPU H100 embarqué ayant exécuté des inférences IA depuis l'orbite. 🔴 DRILLAPP – Nouveau backdoor attribué avec faible confiance au groupe APT Laundry Bear (UAC-0190 / Void Blizzard). Campagne observée en février 2026 contre des organisations ukrainiennes. Abus des paramètres de debug de Microsoft Edge en mode headless pour accéder au système de fichiers, microphone, caméra et écran. Deux variants documentés : LNK puis CPL. Chrome DevTools Protocol utilisé pour contourner les restrictions JavaScript sur les téléchargements distants. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-600-radiocsirt-veille-cyber-du-mardi-17-mars-2026/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #ThreatIntelligence #CTI #WingFTP #KEV #CISA #InfoDisclosure #RCE #CVE #CERTFR #GoogleChrome #MicrosoftEdge #OpenSSL #AzureLinux #Chromium #Starcloud #DataCenter #Space #NVIDIA #GPU #OrbitaleAI #FCC #DRILLAPP #LaundryBear #VoidBlizzard #UAC0190 #APT #Ukraine #Espionnage #EdgeDebug #Backdoor #ChromeDevTools #InfoSec #CERT #SOC #CISO #CyberDefense #OSINT #MalwareAnalysis #BlueTeam

    Post summary

    The episode reports confirmed active exploitation of multiple CVEs across several platforms, highlights the availability of patches, and includes PoC details for a non‑CVE project.

    00000124
    413 followersView on X
  • Techzine NL-BE@Techzinenlbe
    Active Exploitation

    CISA waarschuwt voor actief misbruik van Wing FTP Server-kwetsbaarheden. CVE-2025-47813 en CVE-2025-47812 zijn gepatcht in versie 7.4.4. http://dlvr.it/TRXTDH #Security #CISA #CVE202547812 #CVE202547813 #FTP

    Post summary

    CISA warns that Wing FTP Server vulnerabilities CVE-2025-47813 and CVE-2025-47812 are actively exploited, but the latest patch 7.4.4 addresses the issue.

    00000143
    9.5K followersView on X
  • ARCHIE@archie_sham
    Active Exploitation

    🚨 CISA just added CVE-2025-47813 to the KEV catalog — Wing FTP is leaking server paths via an oversized UID cookie 🍪 Pair that with CVE-2025-47812 (CVSS 10.0 RCE) and you've got a spicy exploit chain 🔥 Patch to v7.4.4. Now. Yesterday. 🛠️ #InfoSec #CyberSecurity #WingFTP https://t.co/i0F28XwfBo

    Post summary

    The tweet announces that CISA has added CVE-2025-47813 to the KEV catalog—signifying active exploitation—and urges users to apply the v7.4.4 patch.

    00000118
    225 followersView on X
  • 1337 Sheets@1337Sheets
    PoC

    Just dropped our WingData 🦅💾 writeup here: https://kzs.m/ajpzyc Dive into the full exploitation chain: 🔹 Recon & Wing FTP Discovery 🔹 Lua Injection RCE (CVE-2025-47812) 🔹 Python Tarfile Filter Bypass (CVE-2025-4517) https://t.co/asLoSPN4ZO

    Post summary

    The tweet announces a writeup that outlines a full exploitation chain for two CVEs, providing technical details but not including direct exploit code or evidence of active attacks.

    0000041
    10 followersView on X
  • @pedri77@pedri77
    Active Exploitation

    A recently disclosed maximum-severity security flaw impacting the Wing FTP Server has come under active exploitation in the wild, according to Huntress. The vulnerability, tracked as CVE-2025-47812 (CVSS score: 10.0), i... https://f.mtr.cool/edzikvyvof

    Post summary

    CVE-2025-47812 in Wing FTP Server, rated CVSS 10.0, is actively exploited in the wild as reported by Huntress, with no patch or workaround mentioned.

    0000034
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwftpserverwing_ftp_server---

Explore more