CVE-2025-47813

9.5 CISA KEV

Wing FTP Server · Wing FTP Server

Wing FTP Server loginok.html allows an authenticated attacker to disclose the full local installation path of the application via an oversized UID cookie value.

Executive summary

Wing FTP Server is vulnerable to an information disclosure flaw that is confirmed to be under active exploitation in the wild.

Vulnerability

This vulnerability involves the improper generation of error messages in the loginok.html component, allowing an authenticated attacker to retrieve the full local installation path by supplying a crafted, long UID cookie value. This provides critical reconnaissance data that can facilitate further exploitation of the host environment.

Business impact

The exposure of the full local installation path significantly lowers the barrier for attackers attempting to conduct more complex, multi-stage attacks against the server. While the CVSS score of 9.5 reflects a high risk, the immediate urgency is driven by the fact that this vulnerability is included in the CISA Known Exploited Vulnerabilities catalog. Unauthorized access to server path information can lead to broader system compromise, unauthorized data exfiltration, or complete service disruption.

Remediation

Immediate Action: Update Wing FTP Server to version 7.4.4 or later immediately to resolve the vulnerable code path.

Proactive Monitoring: Review web server access logs for anomalous requests containing excessively long cookie values or repeated attempts to access loginok.html.

Compensating Controls: Deploy Web Application Firewall rules to inspect and filter incoming HTTP cookies for abnormal length, which may block exploitation attempts while testing or preparing for the software update.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as referenced in the GitHub advisory.

Analyst recommendation

Given the confirmed active exploitation and the inclusion of this CVE in the CISA KEV catalog, organizations must prioritize this update above standard maintenance tasks. Administrators should verify their current version of Wing FTP Server and apply version 7.4.4 without delay to eliminate this reconnaissance vector and secure the server environment against ongoing threats.

More Wing FTP Server CVEs

Sources