CISA Flags Actively Exploited Wing FTP Vulnerability Exposing Server Paths

The U.S. Cybersecurity and Infrastructure Security Agency has added a Wing FTP vulnerability to its KEV catalog, warning of active exploitation that exposes sensitive server path information.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
CISA warning about actively exploited Wing FTP vulnerability leaking sensitive server path information.

CISA warning about actively exploited Wing FTP vulnerability leaking sensitive server path information.

The Cybersecurity and Infrastructure Security Agency (CISA) has added a newly identified security flaw affecting Wing FTP Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.

Vulnerability Details

The vulnerability, tracked as CVE-2025-47813, carries a CVSS score of 4.3 and is classified as an information disclosure flaw. It allows attackers to expose sensitive server path information under specific conditions.

According to CISA, the issue arises when the application improperly handles unusually long values in the UID session cookie, resulting in error messages that reveal internal system paths.

This flaw impacts all versions of Wing FTP Server up to and including version 7.4.3. It has been patched in version 7.4.4 following responsible disclosure by security researcher Julien Ahrens.

Link to Critical RCE Vulnerability

Security experts highlight that version 7.4.4 also addresses a more severe vulnerability, CVE-2025-47812, which carries a maximum CVSS score of 10.0 and enables remote code execution (RCE).

This critical flaw has already been observed under active exploitation since mid-2025, significantly increasing the risk associated with unpatched systems.

Exploitation Techniques Observed

According to findings from Huntress, attackers have leveraged the vulnerabilities to:

  • Download and execute malicious Lua scripts
  • Perform reconnaissance on compromised systems
  • Deploy remote monitoring and management (RMM) tools

These actions enable attackers to maintain persistence and expand access within targeted environments.

Root Cause of the Vulnerability

Research by Julien Ahrens revealed that the endpoint /loginok.html fails to properly validate the UID session cookie value.

If the supplied value exceeds the system’s maximum path length, it triggers an error response that exposes the full local server path. A proof-of-concept exploit demonstrating this behavior has been published on GitHub.

This information disclosure can assist attackers in chaining exploits, particularly when combined with critical vulnerabilities like CVE-2025-47812.

Mitigation and Recommendations

While details about real-world exploitation methods remain limited, cybersecurity authorities warn that even moderate vulnerabilities can become high-risk when used in combination with other flaws.

CISA has urged Federal Civilian Executive Branch (FCEB) agencies to apply patches and secure affected systems by March 30, 2026.

Organizations using Wing FTP Server are strongly advised to:

  • Upgrade to version 7.4.4 or later
  • Monitor systems for unusual activity
  • Restrict access to exposed services
  • Implement strong input validation and logging mechanisms

Broader Cybersecurity Implications

The inclusion of this vulnerability in CISA’s KEV catalog highlights the increasing risk posed by chained vulnerabilities, where seemingly low-severity issues can contribute to larger, more damaging attacks.

As threat actors continue to exploit publicly disclosed flaws, timely patching and proactive monitoring remain critical to maintaining secure network environments.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Vulnerability ManagementNetwork SecurityThreat Intelligence