
On Monday, the U.S. government’s Cybersecurity and Infrastructure Security Agency (CISA) included a medium-risk security issue affecting Wing FTP in its list of Known Exploited Vulnerabilities (KEV), citing proof it’s actively being used by attackers.
The flaw, named CVE-2025-47813 (CVSS score: 4.3), is a vulnerability that reveals sensitive information, specifically the application’s installation directory under certain circumstances.
CISA stated, “Wing FTP Server has a vulnerability where error messages generated when using a long value in the UID cookie contain sensitive information.”
This weakness exists in all software versions up to and including version 7.4.3. Version 7.4.4, released in May after responsible disclosure by RCE Security researcher Julien Ahrens, resolves this issue.
It’s important to note that version 7.4.4 also fixes CVE-2025-47812 (CVSS score: 10.0), another serious vulnerability in the same software that enables remote code execution. This critical bug has been actively exploited since July 2025.
Huntress reported that attackers have been exploiting it to download and run malicious Lua files, gather information system, and install remote management tools.
Ahrens demonstrated in a proof-of-concept (PoC) on GitHub that the “/loginok.html” endpoint doesn’t properly validate the “UID” session cookie’s value. Consequently, if the provided value exceeds the operating system’s maximum path size, an error message is triggered, exposing the server’s complete local path.
The researcher explained, “Successful exploits can provide an authenticated attacker with the application’s local server path, aiding in exploiting vulnerabilities such as CVE-2025-47812.”
Currently, there are no specifics on how the vulnerability is being exploited in the wild, or if it’s being used together with CVE-2025-47812. Due to this recent development, Federal Civilian Executive Branch (FCEB) agencies are advised to implement the necessary patches by March 30, 2026.
#actively #cisa #exploited #exposed #flaw #ftp #news #now #patch #paths #server #warns #wing — News
© Bulletproof Servers. All rights reserved.