ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds a flaw in Wing FTP Server to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2025-47813

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-47813
Path Information Disclosure in Wing FTP Server via UID Cookie

Wing FTP Server versions prior to 7.4.4 disclose the application's full local installation path through loginok.html when a client sends an overly long value in the UID cookie, causing the server to return an error message containing the sensitive path (CWE-209). An attacker triggers the flaw simply by crafting a network request with an oversized UID cookie; per the CVSS vector, low-privilege access suffices and there is no user interaction. The impact of the leak alone is limited (C:L, CVSS 4.3 medium), but the revealed on-disk path is valuable reconnaissance, notably for chaining with the related critical unauthenticated RCE in the same product (CVE-2025-47812), which was publicly documented alongside this bug by the same researcher. All Wing FTP Server deployments running an earlier version are affected, particularly internet-exposed instances. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-16, and its EPSS score of 63% (99th percentile) indicates a high near-term probability of exploitation.

Do: Upgrade to Wing FTP Server 7.4.4 or later, which also remediates the related critical RCE (CVE-2025-47812); Federal/civilian agencies must apply vendor mitigations per the KEV/BOD 22-01 requirement or discontinue use. Administrators of internet-facing instances should review logs for requests to loginok.html with unusually long UID cookie values, confirm the software version in use, and minimize public exposure of the admin/HTTP interface until patched.

4.363% KEV PoC ×2
  • wftpserver (Wing FTP Software) Wing FTP Server All versions before 7.4.4
large≈10,000–50,000 internet-exposed Wing FTP Server instances (public banner scans; total installs including internal deployments unknown)
Full article254 words · extracted from securityaffairs.com · click to collapse

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Wing FTP Server to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Wing FTP Server flaw, tracked as CVE-2025-47813 (CVSS score of 4.3), to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2025-47813 is an information disclosure vulnerability affecting Wing FTP Server versions prior to 7.4.4. The issue occurs in the loginok.html page during the web authentication process.

“loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.” reads the advisory.

The flaw occurs when an attacker sends an excessively long UID cookie, triggering improper input handling that causes the server to return an error revealing the full local installation path. While it does not enable remote code execution, the leak exposes filesystem details that could aid reconnaissance and facilitate further attacks such as path-based exploitation or file inclusion attempts.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerability by March 30, 2026.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, US CISA Known Exploited Vulnerabilities catalog)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/189530/security/u-s-cisa-adds-a-flaw-in-wing-ftp-server-to-its-known-exploited-vulnerabilities-catalog.html