logo

Wing FTP Server Remote Code Execution (CVE-2025-47812) Exploited in the Wild

ID: 6ea9ab06-9327-53cc-b279-25e38ec23d61

STIX ID: report--6ea9ab06-9327-53cc-b279-25e38ec23d61

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-07-10

Date Updated: 2026-04-28

...
...

Huntress observed active exploitation of Wing FTP Server RCE (CVE-2025-47812) against a customer: attackers used null-byte and Lua injection in the username field to inject code into session files, executed commands (attempting to fetch and run a beacon), created backdoor accounts, and left multiple forensic artifacts and IOCs; organizations should update Wing FTP Server to version 7.4.4 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.