¡¾·ì϶¹«¸æ¡¿Wing FTP Server Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-47812)

°ä²¼¹¦·ò 2025-07-02

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Wing FTP Server Ô¶³Ì´úÂëÖ´Ðзì϶

CVE   ID

CVE-2025-47812

·ì϶ÀàÐÍ

RCE

·¢ÏÖ¹¦·ò

2025-07-02

·ì϶ÆÀ·Ö

ÔÝÎÞ

·ì϶µÈ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


Wing FTP ServerÊÇÒ»¿î¿çƽ̨µÄFTP·þÎñÆ÷Èí¼þ£¬Ö§³ÖFTP¡¢FTPS¡¢SFTPºÍHTTP/SºÍ̸£¬ÌṩÎļþ¹²Ïí¡¢Ô¶³ÌÖÎÀíºÍ×Ô¶¯»¯¹¤×÷Ö°ÄÜ¡£ËüºÏÓÃÓÚÓ×ÎÒºÍÆóÒµÓû§£¬Ìṩ¸ßЧµÄÎļþ´«ÊäºÍ°²È«Ö°ÄÜ£¬Ô̺¬¶àÓû§Ö§³Ö¡¢½Ó¼û½ÚÔì¡¢ÈÕÖ¾¼Í¼ºÍ¼ÓÃÜÏνÓ¡£Wing FTP ServerÌṩ¼ò½àµÄWebÖÎÀí½çÃæ£¬Ò×ÓÚÅäÖúÍÊØ»¤£¬ºÏÓÃÓÚWindows¡¢LinuxºÍmacOSµÈ²Ù×÷ϵͳ¡£


2025Äê7ÔÂ2ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Wing FTP Server´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-47812£©£¬¹¥»÷Õß¿Éͨ¹ýÔÚÓû§ÃûÖÐ×¢ÈëNULL×Ö½ÚÈÆ¹ýÉí·ÝÑéÖ¤¡£ÎÞÐèÓÐЧƾ֤£¬¹¥»÷Õß½öÐ踽¼ÓNULL×Ö½Ú£¬¼´¿Éͨ¹ýÉí·ÝÑéÖ¤²¢»ñÈ¡ÓÐЧ»á»°£¬½ø¶øÖ´ÐÐËÁÒâ´úÂë¡£¾ßÌå²û·¢Îª£¬Óû§ÃûÔ̺¬NULL×Ö½Úʱ£¬ÏµÍ³½ö´¦ÖÃNULLǰµÄ²¿ÃÅ£¬µ¼ÖÂÈÏÖ¤ÈÆ¹ý²¢³É¹¦µÇ¼¡£¶ñÒâ´úÂëËæºó¿Éͨ¹ý»á»°Îļþ×¢Èë²¢Ö´ÐУ¬ÓÉÓÚWing FTP ServerÔÚLinuxϵͳÉÏĬÈÏÒÔrootȨÏÞÔËÐУ¬¹¥»÷ÕßÀûÓø÷ì϶¿É»ñµÃÆëÈ«µÄϵͳ½ÚÔìȨÏÞ £»ÔÚWindowsϵͳÉÏ£¬Wing FTP ServerĬÈÏÒÔSYSTEMȨÏÞÔËÐУ¬¹¥»÷ÕßͬÑù¿É»ñµÃ¸ßȨÏ޵ĽÚÔì¡£


¶þ¡¢Ó°ÏìÁìÓò


Wing FTP Server < 7.4.4¡£


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


µ±¼´Éý¼¶ÖÁ Wing FTP Server 7.4.4 »ò¸ü¸ß°æ±¾¡£


ÏÂÔØÁ´½Ó£ºhttps://www.wftpserver.com/zh/download.htm/


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


?¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
?¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
?ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
?¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812