CVE-2025-47812
CISA KEVPublished July 14, 2025 · Updated April 3, 2026
high
Official Description+
Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).
Affected Products
| Vendor | Product |
|---|---|
| Wing FTP Server | Wing FTP Server |
Patch Status
Patch by 2025-08-04
Recommended Actions
- Check if your systems use any of the affected products listed above.
- Apply vendor patches immediately if available.
- This vulnerability is in CISA's Known Exploited Vulnerabilities catalog — prioritize remediation.
- Monitor vendor advisories for updates and additional mitigations.
- Review logs for indicators of compromise related to CVE-2025-47812.