CVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.
- Affected products
- Wing Ftp Server
- Wftpserver Wing Ftp Server
- < 7.4.4
- Fix
- Available
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 92.8% (100th percentile)
- Weakness
- CWE-158
- NVD status
- Analyzed
- Published
- 2025-07-10
CVE-2025-47812 at NVD
43 known exploits for CVE-2025-47812
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2025-47812
CVE-2025-47812-Research
Blackash-CVE-2025-47812
CVE-2025-47812
CVE-2025-47812
CVE-2025-47812
WingFTP-CVE-2025-47812-illdeed
Exploit_CVE-2025-47812
CVE-2025-47812
CVE-2025-47812-Wing-FTP-Server-7.4.3-Unauthenticated-RCE-PoC
CVE-2026-44403-WingFTP-v8.1.2-POC-Exploit
CVE-2025-47812
CVE-2025-47812-PoC
CVE-2025-471812-POC
CVE-2025-47812
CVE-2025-47812
CVE-2025-47812-poc
CVE-2025-47812
CVE-2025-47812-poC
CVE-2025-47812
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
HTB-WingData-Writeup
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
π Wing FTP Server 8.0.7 Remote Code Execution
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
π Wing FTP Server NULL-byte Authentication Bypass
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE)
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing_Ftp_Server
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
Exploit for Cross-site Scripting in Astaro Security_Gateway_Software
Wing FTP Server Authenticated Command Execution