Wing FTP Server < 7.4.4 Multiple Vulnerabilities

critical Nessus Plugin ID 241999

Synopsis

The remote FTP service is affected by multiple vulnerabilities.

Description

The remote FTP server is running a version of Wing FTP Server earlier than 7.4.4. It is, therefore, affected by multiple vulnerabilities, as follows:

- In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts. (CVE-2025-47812)

- loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. (CVE-2025-47813)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to version 7.4.4 or later.

See Also

https://www.wftpserver.com/serverhistory.htm#gotop

http://www.nessus.org/u?6f646db7

http://www.nessus.org/u?ea3bdb1f

Plugin Details

Severity: Critical

ID: 241999

File Name: wing_ftp_server_7_4_4.nasl

Version: 1.2

Type: local

Agent: windows

Family: FTP

Published: 7/11/2025

Updated: 7/14/2025

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 10.0

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-47812

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:wftpserver:wing_ftp_server

Required KB Items: SMB/Wing_FTP/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/10/2025

Vulnerability Publication Date: 7/10/2025

CISA Known Exploited Vulnerability Due Dates: 8/4/2025

Exploitable With

Metasploit (Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812))

Reference Information

CVE: CVE-2025-47812, CVE-2025-47813