CVE-2025-47813
Wing FTP Server vulnerability analysis and mitigation

Overview

CVE-2025-47813 is an information disclosure vulnerability in Wing FTP Server's loginok.html endpoint that leaks the full local installation path of the application when a long value is supplied in the UID session cookie. It affects all Wing FTP Server versions prior to 7.4.4 across Windows, Linux, and macOS. The vulnerability was discovered on 2025-05-01 by Julien Ahrens of RCE Security, patched on 2025-05-14, and publicly disclosed on 2025-06-30; it was formally published to NVD on 2025-07-10 (GitHub Advisory). It carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly).

Technical details

The root cause is classified as CWE-209 (Generation of Error Message Containing Sensitive Information). The loginok.html endpoint fails to properly validate the length of the UID session cookie value; when a value exceeding the maximum path size of the underlying operating system is supplied, the server triggers an error message that includes the full local file system path of the Wing FTP Server installation (GitHub Advisory). Exploitation requires the attacker to be authenticated (low-privilege credentials suffice) and involves sending a crafted HTTP POST request to /loginok.html with an oversized UID cookie. A public proof-of-concept payload is available in the researcher's advisory, and the vulnerability is closely related to CVE-2025-47812 (a critical RCE flaw in the same product), as the disclosed path information directly aids exploitation of that vulnerability (RCE Security).

Impact

Successful exploitation allows an authenticated attacker to obtain the full local installation path of Wing FTP Server on the host system. While the direct impact is limited to confidentiality (no integrity or availability impact), the leaked path information is actively leveraged as a reconnaissance step to facilitate follow-on attacks, most notably exploitation of the companion RCE vulnerability CVE-2025-47812 (GitHub Advisory, CISA KEV). In chained attack scenarios, this information disclosure can contribute to full system compromise, lateral movement, and potential ransomware deployment.

Exploitability

CVE-2025-47813 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-03-16, with a remediation due date of 2026-03-30 (CISA KEV). Public proof-of-concept exploit code is available via the researcher's GitHub advisory and the RCE Security blog (GitHub Advisory, RCE Security). Detection templates have been added to Nuclei (ProjectDiscovery) and Nessus (plugin 241999). The EPSS score is approximately 0.65%, and the KEV listing indicates the vulnerability is known to be used in ransomware-adjacent campaigns (status: Unknown) (CISA KEV). Reports indicate attackers began exploiting the flaw within hours of public disclosure, with over 2,000 Wing FTP Server instances estimated to be exposed online.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Wing FTP Server instances running versions prior to 7.4.4 using tools such as Shodan or Censys, searching for Wing FTP Server web interface banners on common ports (e.g., 80, 443, 8080).
  2. Obtain low-privilege credentials: Acquire valid credentials for the Wing FTP Server instance (e.g., via brute force, credential stuffing, or previously compromised accounts), as the vulnerability requires authentication.
  3. Craft the malicious request: Prepare an HTTP POST request targeting the /loginok.html endpoint with a UID cookie value padded to exceed the maximum OS path length (e.g., 500+ 'A' characters), as demonstrated in the public PoC (GitHub Advisory).
  4. Send the request: Submit the crafted POST request with valid login credentials in the body (username=<user>&password=<pass>) and the oversized UID cookie.
  5. Extract the path: Parse the server's error response, which discloses the full local installation path of Wing FTP Server (e.g., C:\Program Files\Wing FTP Server\ or /opt/wingftp/).
  6. Chain with CVE-2025-47812: Use the disclosed installation path to inform exploitation of the companion RCE vulnerability (CVE-2025-47812), enabling arbitrary code execution on the server (RCE Security).

Indicators of compromise

  • Network: Unusual HTTP POST requests to /loginok.html with an oversized UID cookie value (500+ characters of repeated bytes); requests originating from unexpected or external IP addresses targeting Wing FTP Server web ports.
  • Logs: Wing FTP Server access logs showing POST requests to /loginok.html with abnormally large Cookie header values; error log entries referencing file system path resolution failures triggered by the oversized UID value.
  • File System: No direct file artifacts from this vulnerability alone; however, if chained with CVE-2025-47812, look for unexpected files or web shells in the Wing FTP Server installation directory.
  • Process: Unusual child processes spawned by the Wing FTP Server process following exploitation of the companion RCE vulnerability (CVE-2025-47812), such as command shells or scripting interpreters.

Mitigation and workarounds

The vendor released Wing FTP Server version 7.4.4 on 2025-05-14, which resolves this vulnerability; all installations running versions 7.4.3 and earlier should be upgraded immediately (GitHub Advisory, CISA KEV). CISA's BOD 22-01 requires federal agencies to remediate this vulnerability by 2026-03-30. For systems that cannot be patched immediately, restrict authentication access to Wing FTP Server from untrusted networks and implement network-level controls (e.g., firewall rules, VPN requirements) to limit access to the /loginok.html endpoint from known trusted sources only (CISA KEV).

Community reactions

CISA's addition of CVE-2025-47813 to the KEV catalog on 2026-03-16 generated significant coverage across the security community, with outlets including BleepingComputer, The Hacker News, SecurityWeek, and Security Affairs reporting on active exploitation (Feedly). Researcher Julien Ahrens (RCE Security) published a detailed technical write-up linking CVE-2025-47813 to the more severe CVE-2025-47812 RCE, emphasizing the chained attack risk (RCE Security). Community discussion on Reddit (r/pwnhub, r/SecOpsDaily) and Mastodon highlighted the speed of exploitation following public disclosure and the exposure of over 2,000 servers online. The Canadian Centre for Cyber Security also issued advisory AV25-391 covering Wing FTP Server vulnerabilities.

Additional resources


SourceThis report was generated using AI

Related Wing FTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44403HIGH8.6
  • Wing FTP Server logoWing FTP Server
  • cpe:2.3:a:wftpserver:wing_ftp_server
NoYesMay 12, 2026
CVE-2020-37032HIGH8.6
  • Wing FTP Server logoWing FTP Server
  • cpe:2.3:a:wftpserver:wing_ftp_server
NoYesJan 30, 2026
CVE-2019-25267HIGH8.5
  • Wing FTP Server logoWing FTP Server
  • cpe:2.3:a:wftpserver:wing_ftp_server
NoYesFeb 05, 2026
CVE-2020-37079MEDIUM5.1
  • Wing FTP Server logoWing FTP Server
  • cpe:2.3:a:wftpserver:wing_ftp_server
NoYesFeb 07, 2026
CVE-2022-50934NONEN/A
  • Wing FTP Server logoWing FTP Server
  • cpe:2.3:a:wftpserver:wing_ftp_server
NoYesJan 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management