← back
CVE-2020-37032

Wing FTP Server 6.3.8 - Remote Code Execution

CVSS 8.6 HIGHEPSS 1.0%CWE-78
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.6EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
30 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage the console to send POST requests with malicious commands that trigger operating system execution through the os.execute() function.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →