Critical RCE vulnerability in Wing FTP Server allowing arbitrary Lua code injection through null byte mishandling in web interfaces. Exploitable remotely without authentication, including via anonymous FTP accounts, leading to total server compromise.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-07-10
Added to CISA KEV: 2025-07-14 4 DAYS BETWEEN CVE AND KEV
... internet-facing Wing FTP Server instances are currently vulnerable ... Critical Wing FTP Server vulnerability exploited in the wild (CVE-2025-47812).
Critical vulnerability (CVE-2025-47812) in Wing FTP Server exposed to active exploitation via Lua injection. Immediate patching needed.
CVE-2025-47812.This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).
This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.
Threat researchers at managed cybersecurity platform Huntress created a proof-of-concept exploit for CVE-2025-47812 and show in the video below how hackers could leverage it in attacks: