CISA Flags Actively Exploited Wing FTP Server Flaw
ID: a7cdfb5b-b858-545e-b62c-4e24538e2a32
STIX ID: report--a7cdfb5b-b858-545e-b62c-4e24538e2a32
Feed Name: securityonline.info
CISA has added CVE-2025-47813 — a vulnerability in Wing FTP Server’s /loginok.html endpoint that fails to validate the length of the UID session cookie — to its KEV catalog after reports of active exploitation. An authenticated attacker can supply an oversized UID value to trigger an error that discloses the full local server path, which can be used to facilitate further compromise; agencies must remediate by March 30, 2026, and administrators are advised to upgrade to Wing FTP Server version 7.4.4 or later, audit permissions, and monitor logs for padded cookies and unusual POST requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
