menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

1d

read

138

img
dot

Image Credit: Securityaffairs

Wing FTP Server flaw actively exploited shortly after technical details were made public

  • Hackers are actively exploiting a critical flaw (CVE-2025-47812) in Wing FTP Server, allowing remote code execution with root/system privileges.
  • The vulnerability stems from improper handling of null bytes, enabling injection of malicious Lua code into session files.
  • Even anonymous FTP accounts can be used to trigger code execution with administrative rights on both Linux and Windows systems.
  • Researchers confirmed active exploitation of the flaw shortly after technical details were made public on June 30, urging users to update to server version 7.4.4 or later.

Read Full Article

like

8 Likes

For uninterrupted reading, download the app