CVE-2025-47813
Known exploited · CISA KEV
CVSS 4.3 MEDIUM: loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using… EPSS 63% (99th percentile).
CISA federal remediation date Mar 30
Vulnerabilities · 182 days ago
CISA added CVE-2025-47813, a Wing FTP Server information-disclosure flaw, to its Known Exploited Vulnerabilities list after evidence of active exploitation. The medium-severity bug discloses the server's full local installation path via an overlong UID cookie; it was fixed in Wing FTP Server 7.4.4 but can aid attackers in chaining to other flaws.
Known exploited · CISA KEV
CVSS 4.3 MEDIUM: loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using… EPSS 63% (99th percentile).
CISA federal remediation date Mar 30
3 sources covering this story
CISA Flags Year-Old Wing FTP Vulnerability as Exploited
Tracked as CVE-2025-47813, the flaw leads to the disclosure of the full local installation path of the application.
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
CISA adds Wing FTP CVE-2025-47813 to KEV after active exploitation, exposing server paths and aiding attacks; patch by March 30, 2026.
CISA flags Wing FTP Server flaw as actively exploited in attacks
government agencies to secure their Wing FTP Server instances against an actively exploited vulnerability that may be chained in remote code execution attacks.
Part of the PlainSec briefing for 2026-03-25