VulnerabilitiesMEDIUM

Wing FTP Vulnerability - CISA Flags Active Exploitation Alert

🎯

Basically, a flaw in Wing FTP lets hackers see secret paths on servers.

Quick Summary

CISA has flagged a medium-severity vulnerability in Wing FTP, allowing attackers to leak sensitive server paths. Organizations must upgrade to the latest version to mitigate risks. Immediate action is essential to protect sensitive data and maintain operational integrity.

The Flaw

CISA recently added a new entry to its Known Exploited Vulnerabilities (KEV) catalog, highlighting a medium-severity vulnerability in Wing FTP. This vulnerability, identified as CVE-2025-47813, has a CVSS score of 4.3, which indicates it poses a moderate risk. The issue arises from an information disclosure vulnerability that can leak the installation path of the application under specific conditions.

The vulnerability is triggered when an unusually long value is used in the UID cookie, leading to error messages that inadvertently disclose sensitive information. This flaw affects all versions of Wing FTP prior to version 7.4.4, which was released in May 2025 following a responsible disclosure by researcher Julien Ahrens. Notably, version 7.4.4 also addresses another critical vulnerability, CVE-2025-47812, which allows for remote code execution.

What's at Risk

As of July 2025, active exploitation of this vulnerability has been reported. Attackers have been using it to download and execute malicious scripts, conduct reconnaissance, and install remote monitoring software. The risk is significant as successful exploitation can provide attackers with crucial information about the server, which could facilitate further attacks, especially in conjunction with the more severe CVE-2025-47812.

This vulnerability's exploitation could lead to unauthorized access to sensitive data, potentially compromising the integrity of the affected systems. Organizations using Wing FTP should be particularly vigilant, as the implications of such a breach could be severe, impacting both operational security and customer trust.

Patch Status

The vulnerability has been addressed in version 7.4.4 of Wing FTP. Organizations using earlier versions are strongly encouraged to upgrade to this patched version to mitigate the risks associated with CVE-2025-47813. CISA has recommended that all Federal Civilian Executive Branch (FCEB) agencies apply the necessary fixes by March 30, 2026.

It's crucial for users to regularly check for updates and apply them promptly. Keeping software up to date is one of the most effective ways to protect against known vulnerabilities and potential exploits.

Immediate Actions

To protect against this vulnerability, organizations should take the following steps:

  • Upgrade to Wing FTP version 7.4.4 or later immediately.
  • Monitor for any unusual activity on your servers that could indicate exploitation attempts.
  • Educate staff about the importance of security updates and how to recognize potential phishing attempts that could exploit this vulnerability.

By staying informed and proactive, organizations can significantly reduce their risk of falling victim to this and other vulnerabilities. Cybersecurity is a continuous process, and vigilance is key to maintaining a secure environment.

🔒 Pro insight: Exploitation of CVE-2025-47813 can lead to critical data exposure, especially when combined with CVE-2025-47812's remote execution capabilities.

Original article from

The Hacker News

Read Full Article

Related Pings

CRITICALVulnerabilities

Google Chrome Vulnerabilities - Emergency Fixes Released

Google has issued emergency updates for two serious vulnerabilities in Chrome. These flaws could allow attackers to crash the browser or execute malicious code. Users must update immediately to protect their systems.

SC Media·
HIGHVulnerabilities

Windows 11 Vulnerabilities - Microsoft Releases Critical Update

Microsoft has issued a critical update for Windows 11 to fix serious RRAS vulnerabilities. These flaws could allow remote code execution. Users must apply the patch to safeguard their systems immediately.

SC Media·
MEDIUMVulnerabilities

Vulnerabilities - CISA Adds Wing FTP Server Flaw Alert

CISA has flagged a vulnerability in Wing FTP Server that could expose sensitive information. Organizations using older versions need to act quickly to protect their systems. This flaw could lead to further attacks if not addressed promptly.

Security Affairs·
HIGHVulnerabilities

HPE Vulnerability - Critical Update for Telco Service Orchestrator

HPE has issued a security advisory regarding a vulnerability in the Telco Service Orchestrator. Users of versions before v4.2.12 are at risk. Immediate updates are necessary to protect against potential exploits.

Canadian Cyber Centre Alerts·
CRITICALVulnerabilities

CVE-2025-47812 - Critical Wing FTP Server Vulnerability Alert

A critical vulnerability in Wing FTP Server has been discovered and actively exploited. Users of versions v7.4.3 and prior are at risk. Immediate updates to v7.4.4 are essential for protection.

Canadian Cyber Centre Alerts·
HIGHVulnerabilities

Vulnerabilities - CISA Flags Wing FTP Server Flaw Exploited

CISA has issued a warning about a critical vulnerability in Wing FTP Server. This flaw affects numerous organizations, including federal agencies. Immediate patching is essential to prevent potential remote code execution attacks.

BleepingComputer·