Sploitus

CVE-2025-47812

43 known exploits for CVE-2025-47812

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.

Affected products
Wing Ftp Server
Wftpserver Wing Ftp Server
< 7.4.4
Fix
Available
CVSS 3.1
10.0 CRITICAL
EPSS
92.8% (100th percentile)
Weakness
CWE-158
NVD status
Analyzed
Published
2025-07-10
CVE-2025-47812 at NVD
Authoritative description, scoring and affected products

43 known exploits for CVE-2025-47812

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2025-47812
2026-09-05 KitPloitKITPLOIT
CVE-2025-47812-Research
2026-09-05 KitPloitKITPLOIT
Blackash-CVE-2025-47812
2026-09-05 KitPloitKITPLOIT
CVE-2025-47812
2026-09-05 KitPloitKITPLOIT
CVE-2025-47812
2026-09-05 KitPloitKITPLOIT
CVE-2025-47812
2026-09-05 KitPloitKITPLOIT
WingFTP-CVE-2025-47812-illdeed
2026-09-05 KitPloitKITPLOIT
Exploit_CVE-2025-47812
2026-09-04 KitPloitKITPLOIT
CVE-2025-47812
2026-09-04 KitPloitKITPLOIT
CVE-2025-47812-Wing-FTP-Server-7.4.3-Unauthenticated-RCE-PoC
2026-09-04 KitPloitKITPLOIT
CVE-2026-44403-WingFTP-v8.1.2-POC-Exploit
2026-09-04 KitPloitKITPLOIT
CVE-2025-47812
2026-09-04 KitPloitKITPLOIT
CVE-2025-47812-PoC
2026-09-02 KitPloitKITPLOIT
CVE-2025-471812-POC
2026-09-02 KitPloitKITPLOIT
CVE-2025-47812
2026-09-01 KitPloitKITPLOIT
CVE-2025-47812
2026-09-01 KitPloitKITPLOIT
CVE-2025-47812-poc
2026-08-31 KitPloitKITPLOIT
CVE-2025-47812
2026-08-31 KitPloitKITPLOIT
CVE-2025-47812-poC
2026-08-31 KitPloitKITPLOIT
CVE-2025-47812
2026-08-30 KitPloitKITPLOIT
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2026-05-24 0xS4N4TGGITHUB
HTB-WingData-Writeup
2026-04-27 karimelsheikh1GITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2026-04-09 MajdaeGITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2026-02-24 0xjuarezGITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2026-02-22 popyueGITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2026-02-19 estebanzarateGITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2026-02-18 Nara-sakuraiGITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2026-02-15 matesz44GITHUB
πŸ“„ Wing FTP Server 8.0.7 Remote Code Execution
2025-11-28 indoushkaPACKETSTORMPHP
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2025-07-27 r0otk3rGITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2025-07-17 B1ack4shGITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2025-07-17 blindma1denGITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2025-07-16 rxeriumGITHUB
πŸ“„ Wing FTP Server NULL-byte Authentication Bypass
2025-07-07 Valentin Lobstein, Julien AhrensPACKETSTORMRuby
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2025-07-07 pevinkumar10GITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2025-07-04 ill-deedGITHUB
Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE)
2025-07-02 4m3rr0rEXPLOITDB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2025-07-02 0xgh057r3c0nGITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2025-07-01 0xcan1337GITHUB
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
2025-07-01 4m3rr0rGITHUB
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
2025-06-30 Valentin Lobstein, Julien AhrensMETASPLOITRuby
Exploit for Cross-site Scripting in Astaro Security_Gateway_Software
2019-04-30 MrTuxracerGITHUB
Wing FTP Server Authenticated Command Execution
2014-06-19 Nicholas Nam <nick@executionflow.org>, Imran E. Dawoodjee <imrandawoodjee.infosec@gmail.com>METASPLOITRuby