CVE-2025-47812
About
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.
Rainforest analyst review
The flaw is a null-byte mishandling bug in Wing FTP Server's user and admin web interfaces. The application does not correctly handle embedded '\0' bytes in input, and an attacker uses that to inject arbitrary Lua code into the user session files the server maintains. Because the server later evaluates those session files, the injected Lua runs, giving arbitrary system command execution with the FTP service's privileges, which are root or SYSTEM by default, so a single request yields full server compromise. It can be triggered even through anonymous FTP accounts where those are enabled.
File-transfer servers hold and move exactly the sensitive material organizations exchange, and they are routinely internet-facing to serve external partners, making a pre-auth-caliber RCE that runs as root a high-severity exposure. Public exploitation followed disclosure quickly. Upgrade to Wing FTP Server 7.4.4 or later without delay, disable anonymous access if it is not strictly needed, restrict the web interfaces to trusted networks, and because the exploitation window may predate patching, inspect session-file directories and the host for injected Lua and web shells and rotate service and account credentials.
References
- https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/
- https://www.vicarius.io/vsociety/posts/cve-2025-47812-detection-script-remote-code-execution-vulnerability-in-wing-ftp-server
- https://www.vicarius.io/vsociety/posts/cve-2025-47812-mitigation-script-remote-code-execution-vulnerability-in-wing-ftp-server
- https://www.wftpserver.com
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-47812
- https://www.huntress.com/blog/wing-ftp-server-remote-code-execution-cve-2025-47812-exploited-in-wild
Related CVEs
No related CVEs.
Frequently asked questions
What is CVE-2025-47812?
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise.
How severe is CVE-2025-47812?
CVE-2025-47812 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2025-47812 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2025-47812?
Public advisories list the following as affected: wing ftp server. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2025-47812?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
