
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-47813 is an information disclosure vulnerability in Wing FTP Server's loginok.html endpoint that leaks the full local installation path of the application when a long value is supplied in the UID session cookie. It affects all Wing FTP Server versions prior to 7.4.4 across Windows, Linux, and macOS. The vulnerability was discovered on 2025-05-01 by Julien Ahrens of RCE Security, patched on 2025-05-14, and publicly disclosed on 2025-06-30; it was formally published to NVD on 2025-07-10 (GitHub Advisory). It carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly).
The root cause is classified as CWE-209 (Generation of Error Message Containing Sensitive Information). The loginok.html endpoint fails to properly validate the length of the UID session cookie value; when a value exceeding the maximum path size of the underlying operating system is supplied, the server triggers an error message that includes the full local file system path of the Wing FTP Server installation (GitHub Advisory). Exploitation requires the attacker to be authenticated (low-privilege credentials suffice) and involves sending a crafted HTTP POST request to /loginok.html with an oversized UID cookie. A public proof-of-concept payload is available in the researcher's advisory, and the vulnerability is closely related to CVE-2025-47812 (a critical RCE flaw in the same product), as the disclosed path information directly aids exploitation of that vulnerability (RCE Security).
Successful exploitation allows an authenticated attacker to obtain the full local installation path of Wing FTP Server on the host system. While the direct impact is limited to confidentiality (no integrity or availability impact), the leaked path information is actively leveraged as a reconnaissance step to facilitate follow-on attacks, most notably exploitation of the companion RCE vulnerability CVE-2025-47812 (GitHub Advisory, CISA KEV). In chained attack scenarios, this information disclosure can contribute to full system compromise, lateral movement, and potential ransomware deployment.
CVE-2025-47813 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-03-16, with a remediation due date of 2026-03-30 (CISA KEV). Public proof-of-concept exploit code is available via the researcher's GitHub advisory and the RCE Security blog (GitHub Advisory, RCE Security). Detection templates have been added to Nuclei (ProjectDiscovery) and Nessus (plugin 241999). The EPSS score is approximately 0.65%, and the KEV listing indicates the vulnerability is known to be used in ransomware-adjacent campaigns (status: Unknown) (CISA KEV). Reports indicate attackers began exploiting the flaw within hours of public disclosure, with over 2,000 Wing FTP Server instances estimated to be exposed online.
/loginok.html endpoint with a UID cookie value padded to exceed the maximum OS path length (e.g., 500+ 'A' characters), as demonstrated in the public PoC (GitHub Advisory).username=<user>&password=<pass>) and the oversized UID cookie.C:\Program Files\Wing FTP Server\ or /opt/wingftp/)./loginok.html with an oversized UID cookie value (500+ characters of repeated bytes); requests originating from unexpected or external IP addresses targeting Wing FTP Server web ports./loginok.html with abnormally large Cookie header values; error log entries referencing file system path resolution failures triggered by the oversized UID value.The vendor released Wing FTP Server version 7.4.4 on 2025-05-14, which resolves this vulnerability; all installations running versions 7.4.3 and earlier should be upgraded immediately (GitHub Advisory, CISA KEV). CISA's BOD 22-01 requires federal agencies to remediate this vulnerability by 2026-03-30. For systems that cannot be patched immediately, restrict authentication access to Wing FTP Server from untrusted networks and implement network-level controls (e.g., firewall rules, VPN requirements) to limit access to the /loginok.html endpoint from known trusted sources only (CISA KEV).
CISA's addition of CVE-2025-47813 to the KEV catalog on 2026-03-16 generated significant coverage across the security community, with outlets including BleepingComputer, The Hacker News, SecurityWeek, and Security Affairs reporting on active exploitation (Feedly). Researcher Julien Ahrens (RCE Security) published a detailed technical write-up linking CVE-2025-47813 to the more severe CVE-2025-47812 RCE, emphasizing the chained attack risk (RCE Security). Community discussion on Reddit (r/pwnhub, r/SecOpsDaily) and Mastodon highlighted the speed of exploitation following public disclosure and the exposure of over 2,000 servers online. The Canadian Centre for Cyber Security also issued advisory AV25-391 covering Wing FTP Server vulnerabilities.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."