EXPOSURES › CVE-2025-47812
CVE-2025-47812
HIGH ⌖ ON CISA KEV · EXPLOITEDWing FTP Server exposed to arbitrary code execution due to unpatched null byte vulnerability
Wing FTP Server, a widely-used product, was found to have a critical vulnerability that allowed attackers to inject arbitrary Lua code into user session files, enabling them to execute arbitrary system commands with the privileges of the FTP service. This flaw was actively exploited in the wild, affecting over 84,000 Roundcube Webmail servers.
Shame score — Critical vulnerability actively exploited in the wild with severe command execution implications
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).