U.S. CISA adds a flaw in Wing FTP Server to its Known Exploited Vulnerabilities catalog
ID: 18e6ada2-b182-55a6-863f-6fd79c0d6cba
STIX ID: report--18e6ada2-b182-55a6-863f-6fd79c0d6cba
Feed Name: Security Affairs
Threat Score
CISA added CVE-2025-47813 (CVSS 4.3), an information-disclosure flaw in Wing FTP Server (pre-7.4.4), to its Known Exploited Vulnerabilities catalog. The vulnerability causes the loginok.html page to leak the server's full local installation path when a long UID cookie is sent; while it does not permit remote code execution, the exposed filesystem details can facilitate reconnaissance or path-based attacks. Federal agencies are required to remediate the issue by March 30, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
