CVE-2025-47812
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability
⚠ KEVEPSS 92.9%
Description
Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).
How to fix CVE-2025-47812
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2025-47812 being exploited?
Yes — CVE-2025-47812 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.