Applied Cybernetics Group
Threat intel → detection pipeline
Tuesday, July 14, 2026
Data as of 20:11 UTC

Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

Added to KEV
2025-07-14
Federal due date
2025-08-04
Vendor
Wing FTP Server
Product
Wing FTP Server
EPSS
99.9th percentile (score 0.953, as of 2026-07-13)
NVD CVSS v3.1
Ransomware use
Unknown
ATT&CK
T1059 , T1068 · signal rollup
Upstream
https://nvd.nist.gov/vuln/detail/CVE-2025-47812

CISA short description

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

EPSS percentile is the FIRST.org exploit-probability ranking as of the date noted above; it moves daily. CVSS reflects NVD's analysis at time of publication.