Wing FTP Server Remote Code Execution (CVE-2025-47812) Exploited in the Wild
ID: 6ea9ab06-9327-53cc-b279-25e38ec23d61
STIX ID: report--6ea9ab06-9327-53cc-b279-25e38ec23d61
Feed Name: Huntress Blog
Threat Score
Huntress observed active exploitation of Wing FTP Server RCE (CVE-2025-47812) against a customer: attackers used null-byte and Lua injection in the username field to inject code into session files, executed commands (attempting to fetch and run a beacon), created backdoor accounts, and left multiple forensic artifacts and IOCs; organizations should update Wing FTP Server to version 7.4.4 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
