Wing FTP Server is vulnerable to an unauthenticated remote code execution (RCE) due to improper handling of NULL bytes in the 'username' parameter during the login process. An attacker can inject Lua code into session files and execute it on the server.
Impact
Successful attacks of this vulnerability can result in takeover of the server.