Attackers are actively exploiting Wing FTP Server vulnerability CVE-2025-47812, a critical remote code execution flaw affecting versions prior to 7.4.4 on Windows, Linux, and macOS. The bug stems from improper null-byte handling in the username parameter of the loginok.html web interface, allowing unauthenticated or anonymous attackers to inject malicious Lua code into session files and trigger execution when the application processes that data, resulting in root access on Linux or NT AUTHORITY\SYSTEM on Windows.
Incident reporting shows exploitation began shortly after public disclosure, with attackers probing exposed servers, running reconnaissance commands, creating local user accounts for persistence, attempting payload delivery with certutil, using cURL for possible data exfiltration, and trying to deploy ScreenConnect through malicious Lua files. In one observed case, Microsoft Defender blocked a downloaded payload as Trojan:Win32/Ceprolad.A, and the affected WFTPServer.exe process later crashed before the host was isolated. Defenders are being urged to upgrade immediately to 7.4.4 or later and review session .lua files, session directories, and domain logs for signs of compromise.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
Wing FTP developers released security updates addressing CVE-2025-47812, a critical remote code execution flaw affecting versions earlier than 7.4.4. The vulnerability stems from improper null-byte handling in the web interface's username parameter, enabling Lua injection and command execution.
On 2025-07-01, Huntress observed attackers exploiting CVE-2025-47812 in a customer environment, one day after the vulnerability's public disclosure. The intrusion involved probing from multiple IPs, reconnaissance commands, persistence via local user creation, and attempted payload delivery including a ScreenConnect installer.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.