Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Aug 4, 2025

CVE-2025-47812

High
EPSS 92.5%CISA KEV
Wing FTP Server/Wing FTP Server

Description

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

EPSS — Exploit Probability

92.5%

Higher than 99.7% of all CVEs

Required Action

https://www.wftpserver.com/serverhistory.htm ; https://nvd.nist.gov/vuln/detail/CVE-2025-47812

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
92.5%
CISA KEV
Yes
Ransomware
Unknown
Articles
3

Timeline

Published

Jul 14, 2025

Added to KEV

Jul 14, 2025

Remediation Due

Aug 4, 2025

Affected Product

Wing FTP Server

Wing FTP Server

View all Wing FTP Server CVEs