Wingtech 闻泰科技 A.I CyberSecurity Scoring
Wingtech 闻泰科技
Company Information
Website:http://www.wingtech.com
Employees number:1,859
Number of followers:0
NAICS:
Industry Type:Semiconductors
Homepage:wingtech.com
Wingtech 闻泰科技 Risk Score (AI oriented)
Between 800 and 849
Wingtech 闻泰科技Semiconductors
Updated:
17/03/2026
17/03/2026
834/1000
Good
A
Wingtech 闻泰科技 Global Score (TPRM)
xxxx
Wingtech 闻泰科技Semiconductors
Score locked

Wingtech 闻泰科技Good
Current Score
834A (GOOD)
01000
2 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
835
JULY 2026
835
JUNE 2026
835
MAY 2026
835
APRIL 2026
835
MARCH 2026
836
Vulnerability
16 Mar 2026 • Wingtech 闻泰科技
Wing FTP Server: CISA Issues Alert on Wing FTP Server Vulnerability Used in Attacks
CISA Warns of Active Exploitation in Wing FTP Server Vulnerability (CVE-2025-47813)
834
CRITICAL-2
WIN1773743431
CISA Warns of Active Exploitation in Wing FTP Server Vulnerability (CVE-2025-47813)
On March 16, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability in Wing FTP Server to its Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation by threat actors. Tracked as CVE-2025-47813, the flaw is an information disclosure vulnerability stemming from improper handling of oversized UID cookie values in server requests.
When exploited, the bug triggers an error message that inadvertently exposes sensitive system details, classified under CWE-209. While not directly enabling remote code execution, the leaked data provides attackers with critical insights to bypass security controls and escalate attacks. File transfer servers like Wing FTP are prime targets due to their access to corporate data and network-edge positioning.
CISA has mandated federal agencies to patch or mitigate the vulnerability by March 30, 2026, with private organizations urged to follow suit. Recommended actions include applying vendor-supplied patches, adhering to Binding Operational Directive (BOD) 22-01, and discontinuing use of the software if fixes are unavailable. The inclusion in the KEV catalog confirms real-world attacks, underscoring the urgency for affected entities to secure their infrastructure.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
836
JANUARY 2026
836
DECEMBER 2025
836
NOVEMBER 2025
836
OCTOBER 2025
836
SEPTEMBER 2025
836
MAY 2025
838
Vulnerability
01 May 2025 • Wingtech 闻泰科技
Wing FTP Server: CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
CISA Adds Actively Exploited Wing FTP Vulnerability to KEV Catalog
836
CRITICAL-2
WIN1773736190
CISA Adds Actively Exploited Wing FTP Vulnerability to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-47813, a medium-severity information disclosure flaw in Wing FTP Server, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation. The vulnerability, assigned a CVSS score of 4.3, leaks the application’s installation path when a maliciously crafted UID cookie triggers an error message.
Affected versions include all releases up to and including 7.4.3, with a patch issued in Wing FTP Server 7.4.4 (released in May 2025). The fix was disclosed responsibly by RCE Security researcher Julien Ahrens, who demonstrated in a proof-of-concept (PoC) exploit that the flaw stems from improper validation of the UID cookie in the /loginok.html endpoint. When exploited, the vulnerability reveals the server’s full local path, potentially aiding attackers in chaining exploits including the critical remote code execution (RCE) bug CVE-2025-47812 (CVSS 10.0), which has also been actively exploited since July 2025.
Security firm Huntress reported that threat actors have leveraged CVE-2025-47812 to execute malicious Lua scripts, conduct reconnaissance, and deploy remote monitoring and management (RMM) tools. While it remains unclear whether CVE-2025-47813 is being used in tandem with the RCE flaw, CISA’s inclusion in the KEV catalog underscores its real-world risk.
Federal Civilian Executive Branch (FCEB) agencies are required to remediate the vulnerability by March 30, 2026, though no additional details on the exploitation campaign have been disclosed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Wingtech 闻泰科技 ??
What was Wingtech 闻泰科技's A.I Rankiteo Cyber Score in July 2026 ??
What was Wingtech 闻泰科技's A.I Rankiteo Cyber Score in June 2026 ??
What was Wingtech 闻泰科技's A.I Rankiteo Cyber Score in May 2026 ??
What was Wingtech 闻泰科技's A.I Rankiteo Cyber Score in April 2026 ??
What was Wingtech 闻泰科技's A.I Rankiteo Cyber Score in March 2026 ??
What was Wingtech 闻泰科技's A.I Rankiteo Cyber Score in February 2026 ??
What was Wingtech 闻泰科技's A.I Rankiteo Cyber Score in January 2026 ??
What was Wingtech 闻泰科技's A.I Rankiteo Cyber Score in December 2025 ??
What was Wingtech 闻泰科技's A.I Rankiteo Cyber Score in November 2025 ??
What was Wingtech 闻泰科技's A.I Rankiteo Cyber Score in October 2025 ??
What was Wingtech 闻泰科技's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Wingtech 闻泰科技's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Wingtech 闻泰科技 ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Wingtech 闻泰科技's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?