CVE-2020-37032: Wftpserver Wing FTP Server
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage the console to send POST requests with malicious commands that trigger operating system execution through the os.execute() function.
Affected products
- Wftpserver Wing FTP Server: version 6.3.8 only
Published 2026-01-30. Last modified 2026-06-17.