CyberSec.Space Logo
Back to CVE Browser

CVE-2020-37032

HIGH
8.8
CVSS Severity Score
EPSS Score0.1180%
EPSS Percentile10.11th
PublishedJan 30, 2026
Last ModifiedFeb 18, 2026

Vulnerability Description

Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage the console to send POST requests with malicious commands that trigger operating system execution through the os.execute() function.

Affected Platforms (CPE)

๐Ÿ“ฆ
Wftpserver

Wing Ftp Server

= 6.3.8

References & Advisories

Related Vulnerabilities