PT-2025-17413 · Unknown · Wing Ftp Server

Mrtuxracer

·

Published

2025-04-20

·

Updated

2025-07-11

·

CVE-2025-27889

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Wing FTP Server versions prior to 7.4.4
Description: Wing FTP Server does not properly validate and sanitize the url parameter of the /downloadpass.html API endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.
Recommendations: Update Wing FTP Server to version 7.4.4 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-09369
CVE-2025-27889

Affected Products

Wing Ftp Server