logo

CVSS 10 RCE in Wing FTP exploited within 24 hours, security researchers warn

ID: 8ad41b26-3f61-5e96-8815-0749c159167f

STIX ID: report--8ad41b26-3f61-5e96-8815-0749c159167f

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-07-11

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Huntress researchers observed in-the-wild exploitation of a CVSS 10.0 RCE in Wing FTP Server (CVE-2025-47812) that allows Lua injection via a %00 null byte in the username field, resulting in potential root execution; exploitation began within 24 hours of public disclosure, impacted at least one customer, attackers were unsophisticated and largely unsuccessful, and vendors released a patch in version 7.4.4—organizations are advised to update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.