logo

U.S. CISA adds a flaw in Wing FTP Server to its Known Exploited Vulnerabilities catalog

ID: 18e6ada2-b182-55a6-863f-6fd79c0d6cba

STIX ID: report--18e6ada2-b182-55a6-863f-6fd79c0d6cba

Feed Name: Security Affairs

Threat Score
25/100

Date Published: 2026-03-16

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added CVE-2025-47813 (CVSS 4.3), an information-disclosure flaw in Wing FTP Server (pre-7.4.4), to its Known Exploited Vulnerabilities catalog. The vulnerability causes the loginok.html page to leak the server's full local installation path when a long UID cookie is sent; while it does not permit remote code execution, the exposed filesystem details can facilitate reconnaissance or path-based attacks. Federal agencies are required to remediate the issue by March 30, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.