ZeroHour

CVE-2025-47813

KEV PoC ×2large

Path Information Disclosure in Wing FTP Server via UID Cookie

CISA: Wing FTP Server Information Disclosure Vulnerability

CVSS 3.1
4.3 medium
EPSS
63%p99
Published
()
KEV added
AI analysis

Wing FTP Server versions prior to 7.4.4 disclose the application's full local installation path through loginok.html when a client sends an overly long value in the UID cookie, causing the server to return an error message containing the sensitive path (CWE-209). An attacker triggers the flaw simply by crafting a network request with an oversized UID cookie; per the CVSS vector, low-privilege access suffices and there is no user interaction. The impact of the leak alone is limited (C:L, CVSS 4.3 medium), but the revealed on-disk path is valuable reconnaissance, notably for chaining with the related critical unauthenticated RCE in the same product (CVE-2025-47812), which was publicly documented alongside this bug by the same researcher. All Wing FTP Server deployments running an earlier version are affected, particularly internet-exposed instances. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-16, and its EPSS score of 63% (99th percentile) indicates a high near-term probability of exploitation.

What to do: Upgrade to Wing FTP Server 7.4.4 or later, which also remediates the related critical RCE (CVE-2025-47812); Federal/civilian agencies must apply vendor mitigations per the KEV/BOD 22-01 requirement or discontinue use. Administrators of internet-facing instances should review logs for requests to loginok.html with unusually long UID cookie values, confirm the software version in use, and minimize public exposure of the admin/HTTP interface until patched.

Affected
wftpserver (Wing FTP Software) Wing FTP ServerAll versions before 7.4.4
Estimated exposure
large≈10,000–50,000 internet-exposed Wing FTP Server instances (public banner scans; total installs including internal deployments unknown) — Internet-wide banner scans (Shodan/Censys) typically show on the order of tens of thousands of Wing FTP Server instances exposed on public IPs, and this CVE is tracked under CISA's BOD 22-01 catalog, indicating broad federal/enterprise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

CISA Known Exploited Vulnerability
Affected
Wing FTP Server Wing FTP Server
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
wftpserver
Products
wing ftp server
Weakness
CWE-209
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news