CVE-2025-47812
CVSS v3
10
CRITICAL
Score EPSS
93.2 %
probabilité d’exploitation au 2026-10-05
CISA KEV
Oui
exploitation connue
Exploitation
active
statut SSVC
Description
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.
Vulnérabilité activement exploitée (CISA)
- Date d’ajout
- 2025-07-14
- Échéance de correction
- 2025-08-04
- Usage par rançongiciel
- Unknown
Détails techniques
- Publiée le
- 2025-07-10
- Dernière modification
- 2025-11-05
- Exploit-DB
- EDB-52347
Questions fréquentes
Qu’est-ce que CVE-2025-47812 ?
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.
CVE-2025-47812 est-elle activement exploitée ?
Oui. CVE-2025-47812 figure au catalogue CISA des vulnérabilités activement exploitées (KEV) : son exploitation est confirmée. La CISA impose aux agences fédérales de la corriger avant le 2025-08-04.
Quel est le score CVSS de CVE-2025-47812 ?
CVE-2025-47812 a un score de base CVSS v3 de 10 (gravité CRITICAL).
CVE-2025-47812 touche-t-elle votre environnement ?
Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.
Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite
Pour aller plus loin
- Pour une plateforme de renseignement sur les menaces : indicateurs de malwares, de C2 et de ransomwares via STIX/TAXII.
Autres vulnérabilités 2025 à trier
Classées par probabilité d’exploitation (EPSS).
- CVE-2025-53770KEVMicrosoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2025-49704KEVMicrosoft SharePoint Remote Code Execution Vulnerability
- CVE-2025-3248KEV
- CVE-2025-22457KEV
- CVE-2025-59287KEV
- CVE-2025-0282KEV
- CVE-2025-5777KEVNetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
- CVE-2025-31161KEV