CVE-2025-47813 is an information disclosure vulnerability in Wing FTP Server that reveals the full local installation path through error messages when a long UID cookie value is used. While Wing FTP Server is commonly deployed as internet-facing infrastructure, this vulnerability only leaks path information and does not provide direct system compromise capabilities.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-07-10
Added to CISA KEV: 2026-03-16 249 DAYS BETWEEN CVE AND KEV
CVE-2025-47813 is an information disclosure vulnerability affecting Wing FTP Server that has been confirmed as actively exploited in the wild [4].
While this vulnerability is an information disclosure flaw rather than a remote code execution (RCE) bug, it is considered dangerous because it provides critical reconnaissance information. This path disclosure can be used to facilitate the exploitation of other vulnerabilities, such as CVE-2025-47812, by helping attackers map the file system and target specific application files [2] [5].
This CVE is in CISA's Known Exploited Vulnerabilities Catalog. Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and ... An official website of the United States government Here's how you knowβ¦
Successful exploits can allow an an authenticated attacker to get the local server path of the application, which can help in exploiting vulnerabilities like CVE-2025-47812.
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
Tracked as CVE-2025-47813, the security flaw allows threat actors with low privileges to discover the full local installation path of the application on unpatched servers.
CISA adds Wing FTP CVE-2025-47813 to KEV after active exploitation, exposing server paths and aiding attacks; patch by March 30, 2026.
We added Wing FTP Server information disclosure vulnerability CVE-2025-47813 to our KEV Catalog. Visit go.dhs.gov/Z3Q for more information.