SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-47812

Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

KEVCRITICAL 10.0EPSS 92.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 4 August 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.

CVSS 3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
92.86% probability · 100th percentile
CISA KEV
Listed 14 July 2025 · due 4 August 2025
Weakness
CWE-158
Affected
wftpserver/wing ftp server
Source
cve@mitre.org

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://www.wftpserver.com/serverhistory.htm ; https://nvd.nist.gov/vuln/detail/CVE-2025-47812

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.