CVE-2022-50934: Wing FTP Server - Authenticated RCE
Published Jan 13, 2026
·Updated
Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.
Affected Software
1 affected component
Wing FTP Wing FTP Server<=4.3.8
Event History
Jan 13, 2026
CVE Published
via MITRE·10:52 PM
Rejected
via MITRE·10:52 PM
Data Sourced
via NVD·11:15 PM
Description
Jan 14, 2026
Rejected
via MITRE·06:51 PM
Frequently Asked Questions
1
What is the severity of CVE-2022-50934?
CVE-2022-50934 is considered a high severity vulnerability due to its potential for authenticated remote code execution.
2
How do I fix CVE-2022-50934?
To fix CVE-2022-50934, update Wing FTP Server to version 4.3.9 or later, which addresses this vulnerability.
3
What are the potential impacts of CVE-2022-50934?
The impacts of CVE-2022-50934 include the ability for attackers to execute arbitrary PowerShell commands, potentially leading to data breaches and system compromise.
4
Who is affected by CVE-2022-50934?
CVE-2022-50934 affects users of Wing FTP Server versions 4.3.8 and earlier.
5
How does CVE-2022-50934 work?
CVE-2022-50934 allows attackers to leverage a crafted Lua script payload executed via the admin interface to gain unauthorized command execution capabilities.