CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths

Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a medium-severity security vulnerability affecting Wing FTP to its Known Exploited Vulnerabilities (KEV) database on Monday.

CVE-2025-47813 (CVSS score: 4.3) is an information disclosure vulnerability that, in some circumstances, exposes the application’s installation path. According to CISA, utilizing a lengthy value in the UID cookie causes Wing FTP Server to generate error messages that include sensitive information vulnerabilities.

All software versions before and including version 7.4.3 are impacted by the flaw. After RCE Security researcher Julien Ahrens made a responsible disclosure, the problem was fixed in version 7.4.4, which was released in May.

Notably, CVE-2025-47812 (CVSS score: 10.0), another serious flaw in the same product that permits remote code execution, is also fixed in version 7.4.4. The vulnerability has been actively exploited read more about CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *