Award-winning MFT Software - Diplomat MFT
Award-winning MFT Software - Diplomat MFT

Wing FTP Server Critical Vulnerability Discovered

by | Jul 22, 2025

According to Bleeping Computer, a critical remote code execution vulnerability (CVE-2025-47812) in Wing FTP Server was discovered on July 1 and then used by hackers to bypass authentication and inject malware shortly after the vulnerability was published on July 14. The initial impact appears to have been limited thus far, with one researcher calling the exploitation a “one-off” event that appeared to be a test of the concept described in the CVE. However, The Record reports that security researchers at Censys have since “observed 8,103 exposed devices running Wing FTP Server — 5,004 of which had exposed web interfaces that are potentially vulnerable,” and that subsequent attempts to exploit the vulnerability have been made. It is unknown if any breaches have been associated with the Wing FTP Server vulnerability to date.

Accident or Otherwise?

At Coviant Software we are shocked and saddened when we see this type of exploit in other file transfer products. We take great pride in placing security at the forefront of our development, with training and rigor in implementing our managed file transfer solutions.  When we see poor coding practices of improper security checks on web page input, and even more horrifying loading and executing arbitrary LUA session file, we wonder if anyone on the Wing FTP Server team is even remotely aware of security training, or the OWASP Top 10. One might also wonder if this Chinese company was negligent, or was this an “oversight” leading to potential information supply chain backdoor exploits?

Experts urge all Wing FTP Server users to update to Wing FTP Server version 7.4.4 as soon as possible.

File Transfer a “Popular Target”

The Record reminds its readers that “file transfer tools are a popular target for cybercriminals because of the large companies that use them to send, and sometimes hold, large tranches of data. Widely-used tools from companies like CrushFTP, Cleo, MOVEit, GoAnywhere and Accellion have all faced campaigns of attacks by cybercriminal organizations over the last five years.”

Vendors offering file transfer products understand that their customers use the software to move sensitive information to internal and external sources. Often that information falls under the purview of one or more regulations (like HIPAA, GDPR, GLBA, and others) requiring a high minimum standard of security practices. Features like file encryption, multi-factor authentication, auditable data capture, least privileged access, and network mapping should be table stakes for any file transfer software.

You Have a Choice

Whatever its origin, if you are among the customers affected by the Wing FTP Server vulnerability and are looking for an alternative to Wing FTP, check out our guide for choosing an alternative file transfer solution that is right for your organization. Then check out our Diplomat MFT line of secure, managed file transfer solutions. Diplomat MFT boasts state-of-the-art security features designed to meet the needs of organizations of any size. Here’s a few of the security features you get with Diplomat MFT:

  • Built-in compliance tools like one-click reporting and digital supply chain connection mapping
  • “Dry mode” testing to validate workflow function and security before launching to avoid errors
  • Flexible Roles & LDAP: that establish custom permissions and synchronize with directory integration based on organizational needs
  • Fully automated PGP encryption management
  • Authorized recipient/destination confirmation
  • MFT process data capture for compliance audit reporting and troubleshooting
  • Notifications to communication channels of choice (email, text, Slack, Teams, etc.)

Contact us if you have any questions, want to download a free trial, or would like to schedule a demonstration of our software with a managed file transfer solutions expert equipped to understand how a secure MFT solution can benefit your organization.