Aller au contenu principal
CRITICAL CISA KEV Activement exploitée

CVE-2025-47812

CVSS v3

10

CRITICAL

Score EPSS

93.2 %

probabilité d’exploitation au 2026-10-05

CISA KEV

Oui

exploitation connue

Exploitation

active

statut SSVC

Description

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.

Vulnérabilité activement exploitée (CISA)

Date d’ajout
2025-07-14
Échéance de correction
2025-08-04
Usage par rançongiciel
Unknown

Détails techniques

Publiée le
2025-07-10
Dernière modification
2025-11-05
Exploit-DB
EDB-52347

Questions fréquentes

Qu’est-ce que CVE-2025-47812 ?

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.

CVE-2025-47812 est-elle activement exploitée ?

Oui. CVE-2025-47812 figure au catalogue CISA des vulnérabilités activement exploitées (KEV) : son exploitation est confirmée. La CISA impose aux agences fédérales de la corriger avant le 2025-08-04.

Quel est le score CVSS de CVE-2025-47812 ?

CVE-2025-47812 a un score de base CVSS v3 de 10 (gravité CRITICAL).

CVE-2025-47812 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite