CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2025-47812

🔥 Known Exploited (CISA KEV)CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-07-10
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.

Affected Platforms (CPE)

📦
Wftpserver

Wing Ftp Server

< 7.4.4

References & Advisories

相關漏洞威脅