¡¾Îó²îͨ¸æ¡¿Wing FTP Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-47812)

Ðû²¼Ê±¼ä 2025-07-02

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Wing FTP Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2025-47812

Îó²îÀàÐÍ

RCE

·¢Ã÷ʱ¼ä

2025-07-02

Îó²îÆÀ·Ö

ÔÝÎÞ

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Wing FTP ServerÊÇÒ»¿î¿çƽ̨µÄFTPЧÀÍÆ÷Èí¼þ £¬£¬ £¬£¬£¬ £¬£¬Ö§³ÖFTP¡¢FTPS¡¢SFTPºÍHTTP/SЭÒé £¬£¬ £¬£¬£¬ £¬£¬ÌṩÎļþ¹²Ïí¡¢Ô¶³ÌÖÎÀíºÍ×Ô¶¯»¯Ê¹Ãü¹¦Ð§¡£¡£¡£ËüÊÊÓÃÓÚСÎÒ˽¼ÒºÍÆóÒµÓû§ £¬£¬ £¬£¬£¬ £¬£¬Ìṩ¸ßЧµÄÎļþ´«ÊäºÍÇå¾²¹¦Ð§ £¬£¬ £¬£¬£¬ £¬£¬°üÀ¨¶àÓû§Ö§³Ö¡¢»á¼û¿ØÖÆ¡¢ÈÕÖ¾¼Í¼ºÍ¼ÓÃÜÅþÁ¬¡£¡£¡£Wing FTP ServerÌṩ¾«Á·µÄWebÖÎÀí½çÃæ £¬£¬ £¬£¬£¬ £¬£¬Ò×ÓÚÉèÖúÍά»¤ £¬£¬ £¬£¬£¬ £¬£¬ÊÊÓÃÓÚWindows¡¢LinuxºÍmacOSµÈ²Ù×÷ϵͳ¡£¡£¡£


2025Äê7ÔÂ2ÈÕ £¬£¬ £¬£¬£¬ £¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Wing FTP Server±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2025-47812£© £¬£¬ £¬£¬£¬ £¬£¬¹¥»÷Õß¿Éͨ¹ýÔÚÓû§ÃûÖÐ×¢ÈëNULL×Ö½ÚÈÆ¹ýÉí·ÝÑéÖ¤¡£¡£¡£ÎÞÐèÓÐÓÃÆ¾Ö¤ £¬£¬ £¬£¬£¬ £¬£¬¹¥»÷Õß½öÐ踽¼ÓNULL×Ö½Ú £¬£¬ £¬£¬£¬ £¬£¬¼´¿Éͨ¹ýÉí·ÝÑéÖ¤²¢»ñÈ¡ÓÐÓûỰ £¬£¬ £¬£¬£¬ £¬£¬½ø¶øÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ÏêϸÌåÏÖΪ £¬£¬ £¬£¬£¬ £¬£¬Óû§Ãû°üÀ¨NULL×Ö½Úʱ £¬£¬ £¬£¬£¬ £¬£¬ÏµÍ³½ö´¦Öóͷ£NULLǰµÄ²¿·Ö £¬£¬ £¬£¬£¬ £¬£¬µ¼ÖÂÈÏÖ¤ÈÆ¹ý²¢ÀֳɵǼ¡£¡£¡£¶ñÒâ´úÂëËæºó¿Éͨ¹ý»á»°Îļþ×¢Èë²¢Ö´ÐÐ £¬£¬ £¬£¬£¬ £¬£¬ÓÉÓÚWing FTP ServerÔÚLinuxϵͳÉÏĬÈÏÒÔrootȨÏÞÔËÐÐ £¬£¬ £¬£¬£¬ £¬£¬¹¥»÷ÕßʹÓøÃÎó²î¿É»ñµÃÍêÈ«µÄϵͳ¿ØÖÆÈ¨ÏÞ£»£»£»£»£»£» £»ÔÚWindowsϵͳÉÏ £¬£¬ £¬£¬£¬ £¬£¬Wing FTP ServerĬÈÏÒÔSYSTEMȨÏÞÔËÐÐ £¬£¬ £¬£¬£¬ £¬£¬¹¥»÷ÕßͬÑù¿É»ñµÃ¸ßȨÏ޵ĿØÖÆ¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Wing FTP Server < 7.4.4¡£¡£¡£


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Á¬Ã¦Éý¼¶ÖÁ Wing FTP Server 7.4.4 »ò¸ü¸ß°æ±¾¡£¡£¡£


ÏÂÔØÁ´½Ó£ºhttps://www.wftpserver.com/zh/download.htm/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£


3.3 ͨÓý¨Òé


?°´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬£¬ £¬£¬£¬ £¬£¬ïÔ̭ϵͳÎó²î £¬£¬ £¬£¬£¬ £¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
?ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬£¬ £¬£¬£¬ £¬£¬Ð޸ķÀ»ðǽսÂÔ £¬£¬ £¬£¬£¬ £¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ £¬£¬ £¬£¬£¬ £¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬£¬ £¬£¬£¬ £¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£
?ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬£¬ £¬£¬£¬ £¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
?ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬£¬ £¬£¬£¬ £¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬£¬ £¬£¬£¬ £¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£

?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812