CVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 92.86%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-158
- Published
- 2025-07-10
- Last modified
- 2026-02-26
Affected products
- wftpserver Wing FTP Server
Weakness type
Related vulnerabilities
- CVE-2026-76354 — Path Traversal through Search Head Clustering in Splunk Enterprise
- CVE-2026-70603 — Electron: shell.openPath path validation bypass via embedded null byte
- CVE-2026-47778 — Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)
- CVE-2026-43895 — jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
- CVE-2026-41256 — jq: Embedded NUL truncates top-level jq programs loaded with -f
- CVE-2026-43861 — mutt before 2.3.2 does not check for '\0' in url_pct_decode.
- CVE-2026-43859 — mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
- CVE-2026-33191 — free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error