Skip to content
COOEY

EXPOSURES › CVE-2025-47812

CVE-2025-47812

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-07-14 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-47812 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Wing FTP Server exposed to arbitrary code execution due to unpatched null byte vulnerability

Wing FTP Server, a widely-used product, was found to have a critical vulnerability that allowed attackers to inject arbitrary Lua code into user session files, enabling them to execute arbitrary system commands with the privileges of the FTP service. This flaw was actively exploited in the wild, affecting over 84,000 Roundcube Webmail servers.

Shame score — Critical vulnerability actively exploited in the wild with severe command execution implications

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.