PT-2025-27485 · Unknown · Wing Ftp Server

Julien Ahrens

·

Published

2025-05-10

·

Updated

2025-07-15

·

CVE-2025-47811

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Wing FTP Server versions through 7.4.4
Description: The administrative web interface (listening by default on port 5466) runs with elevated privileges (root or SYSTEM) by default. The web application provides methods to execute arbitrary system commands, which are automatically executed with these high privileges. This situation may lead to privilege escalation, as administrative users of the web interface are not necessarily system administrators.
Recommendations: Versions prior to 7.4.4: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2025-09362
CVE-2025-47811

Affected Products

Wing Ftp Server