008
ID: 05a6d3a2-0194-4796-aee2-9d097e04ea61
STIX ID: report--05a6d3a2-0194-4796-aee2-9d097e04ea61
Threat Score
90/100
Uploaded: 2026-05-14
Published Date: 2026-05-14
Last Modified Date: 2026-05-14
Created by: Thesis Research
TLP:GREEN
...
...
A critical RCE (CVE-2025-47812, CVSS 10.0) in Wing FTP Server allows null-byte Lua injection via the username/login handling, enabling remote execution as root/SYSTEM; active exploitation was observed immediately after disclosure, with threat actors performing reconnaissance, creating accounts, and dropping Lua files to stage a ScreenConnect installer. Users are urged to upgrade to Wing FTP Server 7.4.4 or later; CISA added the vulnerability to its KEV catalog with mandated remediation timelines.
