LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-47812: Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 14, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 4, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-47812 to its Known Exploited Vulnerabilities catalog on Jul 14, 2025, with a federal patch deadline of Aug 4, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute…

CVE-2025-47812 is an improper neutralization of null byte or NUL character vulnerability in Wing FTP Server. It can allow an attacker to inject arbitrary Lua code into user session files and thereby execute system commands with the privileges of the FTP service, which runs as root or SYSTEM by default. For organizations that expose or rely on this FTP server, the issue matters because successful abuse can lead to full host compromise under the service account.

Public detail is limited to the CISA summary and the CWE classification; exact affected versions, attack prerequisites, and patch identifiers must be confirmed against the vendor advisory before any inventory or remediation decision.

How it works

The weakness is classified as CWE-158 (Improper Neutralization of Null Byte or NUL Character). In products that parse or store session data, a null-byte injection can truncate or alter how the application interprets input, allowing unexpected content to be written into files that the server later treats as trusted Lua code.

According to the CISA summary, an attacker who can supply crafted input that reaches user session files can inject arbitrary Lua. When the FTP service loads or evaluates those session files, the injected Lua runs with the privileges of the FTP process. Because the service commonly runs as root on Unix-like systems or SYSTEM on Windows, the resulting commands inherit those elevated rights. No further exploit mechanics, payloads, or preconditions are provided in the available facts; defenders should treat any unauthenticated or low-privilege interaction with session-handling features as potentially dangerous until the vendor advisory is reviewed.

Am I affected? How to find it in your systems

Wing FTP Server is typically deployed as a standalone FTP/SFTP/FTPS service on Windows or Linux hosts that need to share files with external or internal clients. It may appear in DMZs, file-transfer gateways, or departmental servers.

How to remediate

Apply the vendor-supplied update or mitigation instructions for CVE-2025-47812 as the primary action. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-hosted instances, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls appropriate to this class of session-injection flaw.

These steps lower likelihood and impact but do not eliminate the vulnerability; schedule the official patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to host compromise and subsequent data theft or lateral movement. Known ransomware use is not documented for this CVE. If you suspect exposure, examine the FTP host for unauthorized accounts, modified session files, unexpected scheduled tasks, or outbound data transfers. Review any files that were stored or transferred through the service. As a further check, you can run a free exposure scan of your email addresses against known breach data sets to determine whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedWing FTP Server · Wing FTP Server
WeaknessCWE-158
Added to CISA KEVJul 14, 2025
Federal patch deadlineAug 4, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities