HackTheBox
Easy
Aug 08, 2026
•
4 min read
Wingdata - HackTheBox
Easy-difficulty Linux box featuring CVE-2025-47812 unauthenticated RCE against Wing FTP Server 7.4.3 for initial access, offline cracking of a salted SHA-256 password hash for lateral movement, and CVE-2025-4517 PATH_MAX tarfile bypass via a malicious tarball to escalate privileges to root.
#CVE-2025-4517
#CVE-2025-47812
#Hash Cracking
#Linux
#RCE
Read more