CVE-2025-47812 – Remote Code Execution (RCE) – Wing FTP Server

ISGroup Cybersecurity

Wing FTP Server is a cross-platform file transfer application that supports FTP, FTPS, SFTP, HTTP/S, and includes a built-in Lua scripting engine. CVE-2019-5418 allows attackers to execute Lua code at the root/SYSTEM level remotely and, if enabled, without authentication. The vulnerability affects Wing FTP Server versions prior to 7.4.4.

ProductWingFTP sftpd
Date2025-07-14 14:56:57
Information
  • Fix Available
  • Active Exploitation

Technical Summary

The vulnerability stems from improper handling of null bytes (\0) in HTTP POST parameters during login. Specifically, the bug lies in how Wing FTP constructs and writes user session files, such as loginok.html.

Attackers can send a POST request with:

username=ValidUsername%00]]SomeLuaCode--

Or even:

username=anonymous%00]]SomeLuaCode--

In detail:

  • The session for the valid user is created successfully;
  • The null byte terminates the string processing;
  • The ]] closes the previous syntax;
  • The Lua code is stored;
  • The — comments out the previous ]].

After the successful creation of the session object file, attackers send another HTTP GET request to any other endpoint, which triggers the execution of the Lua code.

  • Authenticated/Unauthenticated Attack: The vulnerability requires authentication; however, if enabled server-side, anonymous accounts can also be used for exploitation.
  • Actively Exploited: Numerous security researchers have reported that CVE-2025-47812 is being actively exploited in the wild.

Recommendations

  1. Apply the Patch Immediately: Update all Wing FTP instances to version 7.4.4.
  2. Remove or Harden Anonymous Access: Disable anonymous FTP accounts unless strictly necessary. Authentication currently represents an attack vector.
  3. Monitoring: Analyze session files for anomalies such as excessively large .lua files or those containing suspicious characters. Review logs and monitor POST requests related to loginok.html.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert