CVE-2025-47812: Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.
Other sources
Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wing FTP Serverto a version that resolves this vulnerability.Fixed in 7.4.4 - Compensating control
Apply mitigations per vendor instructions; follow applicable BOD 22-01 guidance for cloud services; discontinue use of Wing FTP Server if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47812?
CVE-2025-47812 is considered a critical vulnerability due to its ability to allow arbitrary code execution.
How do I fix CVE-2025-47812?
To fix CVE-2025-47812, upgrade Wing FTP Server to version 7.4.4 or later.
What does CVE-2025-47812 exploit?
CVE-2025-47812 exploits the mishandling of '\0' bytes in user and admin web interfaces.
What are the potential impacts of CVE-2025-47812?
The potential impacts of CVE-2025-47812 include the execution of arbitrary system commands with elevated privileges.
Is CVE-2025-47812 being actively exploited?
While there are no public reports of active exploitation, the nature of CVE-2025-47812 poses a significant risk to vulnerable systems.