CVE-2025-47813Active Exploitation(wftpserver / wing_ftp_server)

HIGHCVSS 4.3 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 26 mentions and remains active

Immediate actions

  • Patch wftpserver wing_ftp_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

6.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-30. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-209

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wing_ftp_server

Threat summary

  • Active exploitation appears in 47 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 56 mentions across 8 observed days

What's happening

  • Active exploitation reported across 47 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 19 signals
  • Technical details provided in 33 signals
  • General: 6 classified signals
  • Disclosure: 4 classified signals
  • Peaked 5d ago at 26 mentions (2026-03-17); latest day: 1
  • 56 total mentions across 8 days

Affected systems

Vendors
Products
wing_ftp_server

Deep dive

Activity timeline56 mentions / 8d
07132026Mentions · 2026-03-08: 1Mentions · 2026-03-16: 13Mentions · 2026-03-17: 26Mentions · 2026-03-18: 8Mentions · 2026-03-20: 2Mentions · 2026-03-23: 2Mentions · 2026-03-25: 3Mentions · 2026-05-29: 1PoC Mentioned / Linked · 2026-03-17: 1Active Exploitation · 2026-03-16: 10Active Exploitation · 2026-03-17: 23Active Exploitation · 2026-03-18: 6Active Exploitation · 2026-03-20: 2Active Exploitation · 2026-03-23: 2Active Exploitation · 2026-03-25: 3Active Exploitation · 2026-05-29: 1Patch / Workaround · 2026-03-16: 3Patch / Workaround · 2026-03-17: 9Patch / Workaround · 2026-03-18: 4Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-23: 2Technical Details · 2026-03-16: 8Technical Details · 2026-03-17: 18Technical Details · 2026-03-18: 3Technical Details · 2026-03-23: 1Technical Details · 2026-03-25: 303-0803-1603-1703-1803-2003-2303-2505-29
Signal classification4 categories
Active Exploitation
4580.4%
General
610.7%
Disclosure
47.1%
Patch
11.8%
Referenced assets40 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-081
General1
2026-03-1613
Active Exploitation9Disclosure2General2
2026-03-1726
Active Exploitation22Disclosure1General3
2026-03-188
Active Exploitation6Disclosure1Patch1
2026-03-202
Active Exploitation2
2026-03-232
Active Exploitation2
2026-03-253
Active Exploitation3
2026-05-291
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ CISA flags CVE-2025-47813 in Wing FTP as actively exploited. It leaks server paths via cookie errors—low severity, high value. Attackers can pair it with a known RCE flaw already used to deploy malware. 🔗 How it enables real attack chains → https://thehackernews.com/2026/03/cisa-flags-actively-exploited-wing-ftp.html

    Post summary

    CISA reports CVE-2025-47813 in Wing FTP is actively exploited; it leaks server paths through cookie errors and can be chained with a known RCE flaw to deploy malware.

    223167149.9K
    1.1M followersView on X
  • CISA Cyber@CISACyber
    General

    🛡️ We added Wing FTP Server information disclosure vulnerability CVE-2025-47813 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/NPkZxZfR7r

    Post summary

    The tweet announces adding the CVE-2025-47813 information disclosure vulnerability to the DHS KEV catalog, providing a link for more info but offering no technical details, PoC, or exploit references.

    41504155.9K
    293.0K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/16追加) 🛡️No.1544 CVE-2025-47813 Wing FTP Server Information Disclosure Vulnerability =================================== ✅概要 ・深刻度:中⚠️ 4.3 (CVSS Base) / MITRE (CNA) ・種別:エラーメッセージによる機微情報露出 (CWE-209) ・CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Wing FTP Server 7.4.4 未満の loginok.html において、UID cookie に長い値を使用した場合、アプリケーションのローカルインストールパスが漏えいする脆弱性。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・攻撃者が有効な権限レベルを持つこと ・脆弱な Wing FTP Server 7.4.4 未満が稼働していること ✅悪用時影響 ・ローカルインストールパスの漏えい ・環境把握のための内部情報露出 ・後続攻撃の足掛かり ✅悪用事例等に関する情報 ・PoC/Exploit:公開情報確認できず ・ITW:公開情報確認できず ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-47813 https://www.wftpserver.com/serverhistory.htm CISA Adds One Known Exploited Vulnerability to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/03/16/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CISA confirmed CVE-2025-47813 is actively exploited in the wild; the vulnerability is an information disclosure in Wing FTP Server, but no PoC or exploit code are publicly available.

    010614.1K
    42.7K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    CISA adds a Wing FTP Server flaw (CVE-2025-47813) to its KEV catalog. The actively exploited cookie vulnerability exposes internal server paths. Update now. #WingFTPServer #CVE #CISAKEV #CyberSecurity #InfoSec #ThreatIntel #Vulnerability #PathDisclosure https://securityonline.info/cisa-urgent-mandate-actively-exploited-wing-ftp-server-cookie-flaw/ https://t.co/XlGusOTc2z

    Post summary

    CISA has listed CVE‑2025‑47813 as an actively exploited flaw that discloses server paths via a cookie vulnerability, urging users to update, but no PoC or patch details are provided.

    02050759
    10.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    CISA added CVE-2025-47813 to the Known Exploited Vulnerabilities catalog after active exploitation in Wing FTP. This info leak exposes server paths via an overlong UID cookie. Patch available in Wing FTP 7.4.4. #InfoLeak #WingFTP #USA https://ift.tt/vPIz0AH

    Post summary

    CISA reports CVE-2025-47813 is actively exploited in Wing FTP, leaking server paths through an overlong UID cookie, and a patch is available in version 7.4.4.

    00031263
    3.7K followersView on X
  • Criminal IP@CriminalIP_US
    Active Exploitation

    📡Wing FTP Vulnerability → RCE Attack Chain Risk​ CVE-2025-47813 is actively exploited and added to CISA KEV.​ On its own, it exposes server paths, but the real risk appears when chained.​ ​ Combined with CVE-2025-47812 (RCE):​ Exposure → Path Leak → RCE → System Compromise​ Criminal IP analysis shows:​ ✔️ Multiple Wing FTP services internet-exposed​ ✔️ status_code:200 interfaces directly accessible​ ✔️ Some management pages publicly reachable​ Even “medium” vulnerabilities can escalate when exposure exists.​ ​ 🔎 Full analysis​ https://www.criminalip.io/knowledge-hub/blog/33366​ ​ #ThreatIntelligence #CyberSecurity #RCE #ASM

    Post summary

    The post confirms CVE-2025-47813 is being actively exploited in the wild, detailing a path‑leak to RCE chain with CVE-2025-47812, and highlights the exposure of internet‑accessible Wing FTP services.

    00020261
    4.8K followersView on X
  • Dark Web Monitoring - Darknetsearch.com@CtiKaduu
    Patch

    🚨http://Darknetsearch.com NEW POST: 🌐https://darknetsearch.com/knowledge/news/en/cve-2025-47813-guide-key-risks-and-fixes-explained/ #Cybersecurity #DataBreach #InfoSecurity #PrivacyProtection #CyberThreats #RiskManagement #DarkWebMonitoring #DataProtection #CyberAwareness #HackerNews Ask for a DEMO.📽️

    Post summary

    The post promotes a guide detailing risks and fixes for CVE‑2025‑47813; it does not provide PoC, exploit code, or evidence of active exploitation.

    00110263
    166 followersView on X
  • VulnDex@VulnDex
    Disclosure

    🔎 Trending CVE CVE-2025-47813 im Wing FTP Server (<7.4.4) ermöglicht das Offenlegen sensibler Informationen über manipuliertes UID-Cookie. Bereits im CISA KEV-Katalog gelistet. Kombination mit weiteren Schwachstellen möglich. Details: https://vulndex.at/cve/CVE-2025-47813 https://t.co/BKW92Gdqnl

    Post summary

    The tweet announces CVE-2025-47813, a sensitive information disclosure in Wing FTP Server via a manipulated UID cookie, and notes its inclusion on the CISA KEV list, indicating known exploitation.

    0101089
    2 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性を1件カタログに追加 CISA Adds One Known Exploited Vulnerability to Catalog #CISA (Mar 16) CVE-2025-47813 Wing FTPサーバーの情報漏洩の脆弱性 https://www.cisa.gov/news-events/alerts/2026/03/16/cisa-adds-one-known-exploited-vulnerability-catalog

    Post summary

    CISA added CVE‑2025‑47813, an information‑leak flaw in Wing FTP Server, to its catalog of known exploited vulnerabilities, confirming its use in real‑world attacks.

    00020354
    4.7K followersView on X
  • Criminal IP Japan@CriminalIP_JP
    Active Exploitation

    📁Wing FTP情報漏えい脆弱性(CVE-2025-47813)​ 最近、Wing FTP Serverで発見された情報漏えい脆弱性が実際の攻撃に悪用され、KEVに追加されました。この脆弱性は、長いUIDクッキー値の処理過程で​サーバーのローカルインストールパスが露出する問題です。​ ​ 💡 Criminal IP 観点の分析​ ▪ インターネット上に露出したWing FTPサービスを多数確認​ ▪ Webインターフェースへ直接アクセス可能な環境の存在​ ▪ バナーやレスポンス情報からバージョン・構成の推定が可能​ 特に本脆弱性は単体よりも、RCE脆弱性(CVE-2025-47812)と組み合わせることでリスクが増大します。パス情報取得 → 脆弱バージョン特定 → コード実行といった実際の攻撃チェーンにつながる可能性があります。​ 🔎 詳細分析はこちら​ https://www.criminalip.io/ja/knowledge-hub/blog/8309​ #サイバーセキュリティ #脆弱性 #脅威インテリジェンス

    Post summary

    CVE‑2025‑47813 was discovered in Wing FTP Server, actively exploited in the wild, and added to KEV; the vulnerability causes local path exposure via UID cookie handling, but no patch or PoC is provided.

    00001364
    1.4K followersView on X
  • twelvesec@twelvesec
    Active Exploitation

    #CISA on Monday added a medium-severity #security flaw (CVE-2025-47813) impacting Wing FTP to its Known Exploited Vulnerabilities catalogue. #CyberSecurity #InfoSec https://buff.ly/H9bOibI https://t.co/hV4tSQk1hi

    Post summary

    CISA identified CVE-2025-47813 as a medium‑severity flaw actively exploited in the wild, but the tweet does not provide exploitation code, patch information, or technical details.

    00001148
    1.5K followersView on X
  • nin_tech@nin_tech_x
    Active Exploitation

    CISA-Meldung: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-47813

    Post summary

    CISA links CVE-2025-47813 to its known‑exploited vulnerabilities catalog, confirming that it is being exploited in the wild, but the statement contains no proof‑of‑concept, exploit code, patch, or technical details.

    1000072
    232 followersView on X
  • nin_tech@nin_tech_x
    Active Exploitation

    ⚠️ CISA bestätigt aktive Ausnutzung kritischer Schwachstelle in Wing FTP Server (CVE-2025-47813). Die Lücke als Information Disclosure wurde am 16. März in den Known Exploited Vulnerabilities (KEV) Katalog aufgenommen. https://t.co/FoZFtHAleQ

    Post summary

    CISA confirms that CVE-2025-47813 in Wing FTP Server is actively exploited and has been added to the Known Exploited Vulnerabilities catalog.

    1000084
    232 followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    👁️Worldプロジェクト、エージェントコマースの人間関与認証ツールをリリース ⚠️米CISA、昨年公表のWing FTPの脆弱性が悪用されたと警告(CVE-2025-47813) 〜サイバーアラート3月18日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44665/

    Post summary

    CISA has confirmed exploitation of the Wing FTP vulnerability (CVE-2025-47813) in the wild, with no PoC, exploit, patch or technical detail disclosed.

    00001225
    1.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CISA adds Wing FTP Server CVE-2025-47813 to KEV catalog after active exploitation. Path disclosure flaw chains with RCE bug patched in May 2025 - federal agencies have 2 weeks to remediate. #DFIR_Radar https://t.co/jGadPfb4Cu

    Post summary

    The tweet announces that CISA has catalogued CVE-2025-47813 as a key active exploit, noting a path disclosure flaw that leads to a patched RCE bug and urging federal agencies to remediate within two weeks.

    1000015
    19 followersView on X
  • TechNadu@TechNadu
    Active Exploitation

    🛡️ @CISACyber adds new KEV entry 🚨 CVE-2025-47813 (Wing FTP Server) • Actively exploited • Info disclosure risk Patch ASAP. 💬 Are you tracking KEV updates? 🔁 Follow @TechNadu #CyberSecurity #CISA #Infosec https://t.co/FVOTHjp0hg

    Post summary

    A new CVE for Wing FTP Server is reported as actively exploited, with an urgent patch recommended.

    10000129
    10.0K followersView on X
  • Shah Sheikh@shah_sheikh
    Active Exploitation

    CISA Flags Year-Old Wing FTP Vulnerability as Exploited: Tracked as CVE-2025-47813, the flaw leads to the disclosure of the full local installation path of the application. The post CISA Flags Year-Old Wing FTP Vulnerability as Exploited appeared first… https://www.securityweek.com/cisa-flags-year-old-wing-ftp-vulnerability-as-exploited/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    CISA indicates CVE-2025-47813, a path disclosure flaw in Wing FTP, is being actively exploited in the wild, but no PoC, tool, or patch details are provided.

    0100095
    2.2K followersView on X
  • Techzine@techzine
    Active Exploitation

    CISA warns of active exploitation of Wing FTP Server vulnerabilities. CVE-2025-47813 and CVE-2025-47812 have been patched in version 7.4.4. http://dlvr.it/TRXRtf #Security #CISA #CVE202547812 #CVE202547813 #FTP - Follow for more

    Post summary

    CISA warns that CVE-2025-47812 and CVE-2025-47813 are actively exploited, and that these issues have been fixed in Wing FTP Server v7.4.4, urging immediate patching.

    00010100
    9.0K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2010-5139 2 - CVE-2026-24291 3 - CVE-2019-17571 4 - CVE-2025-47813 5 - CVE-2026-25172 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs without providing any additional technical or operational context.

    00010212
    1.7K followersView on X
  • Zero-sum@projectzerosum
    Active Exploitation

    1/ CISA just put Wing FTP on KEV for CVE-2025-47813. Yes, a “medium” bug. Yes, it’s being exploited. Security teams keep learning the same lesson: attackers do not care about your CVSS religion. https://t.co/BuO10iEjx1

    Post summary

    CISA has classified CVE-2025-47813 as an actively exploited vulnerability. The advisory emphasizes its real-world abuse and the urgency for remediation.

    1000081
    26 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwftpserverwing_ftp_server---

Explore more