Security
Loading…

CVE-2025-47812

UNKNOWNKnown Exploited
Description

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

Timeline
Published:July 14th, 2025 12:00 AM
Last modified:July 14th, 2025 12:00 AM
Added to KEV:July 14th, 2025
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Wing FTP Server

Products

Wing FTP Server
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute