CVE-2020-37032

HIGH WAF: High
CVSS 8.8 Published: 2026-01-30
CWE-78

Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage the console to send POST requests with malicious commands that trigger operating system execution through the os.execute() function.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
wftpserverwing_ftp_server6.3.8

References

Back to CVE Database