Executive brief
Wing FTP Server, a file transfer solution used for corporate data exchange, is vulnerable to an information disclosure flaw. An attacker can force the system to reveal its internal file directory structure and installation path. This information can be used by malicious actors to plan more sophisticated attacks against the server's underlying operating system.
Technical details
An information disclosure vulnerability exists in Wing FTP Server's loginok.html component due to improper error handling (CWE-209). When a user provides an excessively long value in the UID cookie, the application generates an error message that reveals the full local installation path of the application. This is a network-based attack that requires low privileges (authenticated user). While the disclosure itself does not allow for code execution, it provides critical reconnaissance data for attackers. The vulnerability is addressed in version 7.4.4. Notably, this flaw has been observed in the wild and is included in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Affected products
- Wing FTP Server Wing FTP Server versions before 7.4.4
Timeline
- 2025-07-10: disclosed: Initial CVE publication
- 2026-03-16: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-07-10: patched: Fixed in version 7.4.4