<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Wing FTP Server</title><description>Actively exploited vulnerabilities affecting Wing FTP Server products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/wing-ftp-server.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-47813 — Wing FTP Server Information Disclosure Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-47813</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-47813</guid><description>Wing FTP Server leaks sensitive information through error messages triggered by sending an oversized value in the UID cookie. Attackers can exploit this without needing valid credentials, potentially harvesting internal details — such as file paths, software versions, or configuration data — that help them map the environment and plan deeper attacks. Because this is an information disclosure flaw in a widely used FTP server product, it lowers the bar for follow-on compromise and is now tracked as an actively exploited vulnerability by CISA.</description><pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate><category>Wing FTP Server</category><category>Wing FTP Server</category></item><item><title>CVE-2025-47812 — Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-47812</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-47812</guid><description>Wing FTP Server fails to properly handle null bytes in user session files, allowing an attacker to inject arbitrary Lua code into those files. Because the FTP service typically runs as root on Linux or SYSTEM on Windows, successful exploitation gives an attacker full system-level command execution — effectively complete control of the host. Any organization running Wing FTP Server should treat this as a critical-severity, actively tracked vulnerability requiring immediate attention.</description><pubDate>Mon, 14 Jul 2025 00:00:00 GMT</pubDate><category>Wing FTP Server</category><category>Wing FTP Server</category></item></channel></rss>