CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a medium-severity security vulnerability affecting Wing FTP to its Known Exploited Vulnerabilities (KEV) database on Monday.
CVE-2025-47813 (CVSS score: 4.3) is an information disclosure vulnerability that, in some circumstances, exposes the application's installation path. According to CISA, utilizing a lengthy value in the UID cookie causes Wing FTP Server to generate error messages that include sensitive information vulnerabilities.
All software versions before and including version 7.4.3 are impacted by the flaw. After RCE Security researcher Julien Ahrens made a responsible disclosure, the problem was fixed in version 7.4.4, which was released in May.
Notably, CVE-2...

