# Wing FTP Server RCE Exploit Chain — Lua Code Injection via NULL Byte (CVE-2025-47812 CVSS 10.0 + CVE-2025-47813)

> Critical exploit chain in Wing FTP Server before 7.4.4 achieves unauthenticated remote code execution as SYSTEM/root. CVE-2025-47813 (CVSS 4.3) discloses the full server installation path via crafted UID cookies, while CVE-2025-47812 (CVSS 10.0) exploits NULL byte mishandling in the username parameter to inject arbitrary Lua code into session files, which execute with service-level privileges. Public PoC available since June 2025; active exploitation confirmed by Huntress since July 1, 2025. CISA KEV additions: CVE-2025-47812 on July 14, 2025; CVE-2025-47813 on March 16, 2026.

- **Published:** 2026-03-17T12:00:00Z
- **Last reviewed:** 2026-03-17T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0241
- **ID:** TL-2026-0241
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-47812, CVE-2025-47813

## Description

Wing FTP Server versions prior to 7.4.4 contain a critical exploit chain combining two vulnerabilities that together achieve unauthenticated remote code execution with SYSTEM (Windows) or root (Linux/macOS) privileges.

## CVE-2025-47812 — Lua Code Injection via NULL Byte (CVSS 10.0)

The core RCE vulnerability stems from improper handling of NULL bytes (\0) in both the user and admin web interfaces. The exploit chain operates through four interconnected weaknesses:

1. **NULL Byte Truncation in Authentication**: The c_CheckUser() function uses strlen() on the provided username. When a NULL byte (%00) is injected into the username, strlen() truncates the string at that point, causing authentication to succeed for the portion before the NULL byte. This allows exploitation via anonymous FTP accounts or any known credentials.

2. **Unsanitized Session Creation**: Despite authentication validating only the truncated portion, the rawset(_SESSION, 'username', username) call in loginok.html preserves the entire unsanitized username from request parameters, including the NULL byte and all subsequent characters.

3. **Lua Script Session Storage**: Wing FTP Server stores session data as executable Lua scripts on disk. The injected payload — crafted as valid Lua code after the NULL byte — is written directly into the session file.

4. **Session File Execution**: When an authenticated endpoint (specifically /dir.html) is accessed with the session UID cookie, the SessionModule.load() function executes session files via loadfile(filepath) followed by f(), triggering the injected Lua payload with full service-level privileges.

A typical exploit payload follows this structure: `anonymous%00]]%0dlocal+h+%3d+io.popen("command")%0dlocal+r+%3d+h%3aread("*a")%0dh%3aclose()%0dprint(r)%0d--` where `]]` closes the existing Lua table syntax, `io.popen()` executes arbitrary system commands, and `--` comments out remaining session data.

The attack requires only two HTTP requests: (1) a POST to /loginok.html with the crafted payload in the username parameter, and (2) a GET to /dir.html with the returned UID cookie to trigger execution.

## CVE-2025-47813 — Installation Path Disclosure (CVSS 4.3)

The loginok.html endpoint in Wing FTP Server before 7.4.4 discloses the full local installation path when an excessively long string is submitted in the UID cookie. This information disclosure (CWE-209) reveals sensitive server configuration details that aid exploitation of CVE-2025-47812 by exposing the exact filesystem location of session files.

## Active Exploitation

Huntress observed the first in-the-wild exploitation on July 1, 2025 — one day after Julien Ahrens (RCE Security) published the detailed vulnerability write-up and PoC on June 30, 2025. The patch (v7.4.4) had been available since May 14, 2025, but many installations remained unpatched.

Multiple distinct threat actors were observed exploiting the same victim from different IP addresses. Post-exploitation activity included network reconnaissance, creation of new local user accounts for persistence, attempted download and execution of malicious batch files, and deployment of ScreenConnect (ConnectWise Control) remote monitoring and management software. Microsoft Defender blocked several malicious activities on the compromised host.

Censys identified approximately 8,103 exposed Wing FTP Server instances as of July 9, 2025, with roughly 5,004 having exposed web interfaces potentially vulnerable to exploitation. Only 105 devices publicly reported version numbers.

## Related Vulnerabilities

CVE-2025-47811 is an additional privilege escalation vulnerability in Wing FTP Server that remains UNFIXED even in v7.4.4. CVE-2025-27889, an information disclosure flaw revealing cleartext passwords, was fixed in v7.4.3 (released March 26, 2025).

## Impact

Successful exploitation grants full SYSTEM/root-level command execution on the underlying server, enabling complete compromise of the host including data exfiltration, lateral movement, ransomware deployment, and persistent backdoor installation. The vulnerability is particularly dangerous because Wing FTP Server typically runs with maximum privileges by default and is commonly deployed as an internet-facing file transfer solution.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1136 Create Account
- T1505 Server Software Component
- T1068 Exploitation for Privilege Escalation
- T1027 Obfuscated Files or Information
- T1070 Indicator Removal
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087 Account Discovery
- T1219 Remote Access Tools
- T1071 Application Layer Protocol
- T1485 Data Destruction

## Sources

- [NVD — CVE-2025-47812](https://nvd.nist.gov/vuln/detail/CVE-2025-47812)
- [NVD — CVE-2025-47813](https://nvd.nist.gov/vuln/detail/CVE-2025-47813)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [Huntress — Wing FTP Server RCE (CVE-2025-47812) Exploited in the Wild](https://www.huntress.com/blog/wing-ftp-server-remote-code-execution-cve-2025-47812-exploited-in-wild)
- [Exploit-DB — Wing FTP Server 7.4.3 Unauthenticated RCE (EDB-52347)](https://www.exploit-db.com/exploits/52347)
- [GitHub PoC — CVE-2025-47812 Exploit](https://github.com/4m3rr0r/CVE-2025-47812-poc)
- [Censys Advisory — Unauthenticated RCE in Wing FTP Server](https://censys.com/advisory/cve-2025-47812/)
- [ZeroPath — Wing FTP Server NULL Byte RCE Analysis](https://zeropath.com/blog/wing-ftp-server-null-byte-rce-cve-2025-47812)
- [Help Net Security — Critical Wing FTP Vulnerability Exploited in the Wild](https://www.helpnetsecurity.com/2025/07/11/critical-wing-ftp-server-vulnerability-exploited-in-the-wild-cve-2025-47812/)
- [The Hacker News — CISA Flags Actively Exploited Wing FTP Vulnerability](https://thehackernews.com/2026/03/cisa-flags-actively-exploited-wing-ftp.html)
- [Fidelis Security — CVE-2025-47812 Wing FTP RCE Vulnerability](https://fidelissecurity.com/vulnerabilities/cve-2025-47812/)
- [Cynet — Wing FTP Post Authentication RCE CVE-2025-47812](https://www.cynet.com/blog/wing-ftp-post-authentication-rce-cve-2025-47812/)
- [SecurityWeek — CISA Flags Year-Old Wing FTP Vulnerability as Exploited](https://www.securityweek.com/cisa-flags-year-old-wing-ftp-vulnerability-as-exploited/)
- [Wing FTP Server Security Advisory](https://www.wftpserver.com/security)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0241
