logo

008

ID: 05a6d3a2-0194-4796-aee2-9d097e04ea61

STIX ID: report--05a6d3a2-0194-4796-aee2-9d097e04ea61

Threat Score

90/100

Uploaded: 2026-05-14

Published Date: 2026-05-14

Last Modified Date: 2026-05-14

Created by: Thesis Research

TLP:GREEN
...
...
A critical RCE (CVE-2025-47812, CVSS 10.0) in Wing FTP Server allows null-byte Lua injection via the username/login handling, enabling remote execution as root/SYSTEM; active exploitation was observed immediately after disclosure, with threat actors performing reconnaissance, creating accounts, and dropping Lua files to stage a ScreenConnect installer. Users are urged to upgrade to Wing FTP Server 7.4.4 or later; CISA added the vulnerability to its KEV catalog with mandated remediation timelines.