CVE-2025-47813
KEV PoC ×2largePath Information Disclosure in Wing FTP Server via UID Cookie
CISA: Wing FTP Server Information Disclosure Vulnerability
Wing FTP Server versions prior to 7.4.4 disclose the application's full local installation path through loginok.html when a client sends an overly long value in the UID cookie, causing the server to return an error message containing the sensitive path (CWE-209). An attacker triggers the flaw simply by crafting a network request with an oversized UID cookie; per the CVSS vector, low-privilege access suffices and there is no user interaction. The impact of the leak alone is limited (C:L, CVSS 4.3 medium), but the revealed on-disk path is valuable reconnaissance, notably for chaining with the related critical unauthenticated RCE in the same product (CVE-2025-47812), which was publicly documented alongside this bug by the same researcher. All Wing FTP Server deployments running an earlier version are affected, particularly internet-exposed instances. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-16, and its EPSS score of 63% (99th percentile) indicates a high near-term probability of exploitation.
What to do: Upgrade to Wing FTP Server 7.4.4 or later, which also remediates the related critical RCE (CVE-2025-47812); Federal/civilian agencies must apply vendor mitigations per the KEV/BOD 22-01 requirement or discontinue use. Administrators of internet-facing instances should review logs for requests to loginok.html with unusually long UID cookie values, confirm the software version in use, and minimize public exposure of the admin/HTTP interface until patched.
| wftpserver (Wing FTP Software) Wing FTP Server | All versions before 7.4.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
- Affected
- Wing FTP Server Wing FTP Server
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- wftpserver
- Products
- wing ftp server
- Weakness
- CWE-209
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N