CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
ID: bfe03500-310f-5d3c-b082-416edfebfdd0
STIX ID: report--bfe03500-310f-5d3c-b082-416edfebfdd0
Feed Name: The Hacker News
Threat Score
CISA added CVE-2025-47813 (info disclosure, CVSS 4.3) in Wing FTP Server to its KEV list after active exploitation was observed; the bug leaked the application installation path via an overlong UID cookie and was fixed in version 7.4.4 (released alongside a patch for a separate critical RCE, CVE-2025-47812).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
