cscli appsec-rules install crowdsecurity/vpatch-CVE-2025-478121## autogenerated on 2025-08-06 13:53:062name: crowdsecurity/vpatch-CVE-2025-478123description: 'Detects Wing FTP Server <= 7.4.3 RCE via Lua code injection in username parameter during login.'4rules:5 - and:6 - zones:7 - URI8 transform:9 - lowercase10 match:11 type: contains12 value: /loginok.html13 - zones:14 - BODY_ARGS15 variables:16 - username17 transform:18 - lowercase19 - urldecode20 match:21 type: contains22 value: ']]'23 - zones:24 - BODY_ARGS25 variables:26 - username27 transform:28 - lowercase29 - urldecode30 match:31 type: contains32 value: 'io.popen('3334labels:35 type: exploit36 service: http37 confidence: 338 spoofable: 039 behavior: 'http:exploit'40 label: 'Wing FTP Server - RCE'41 classification:42 - cve.CVE-2025-4781243 - attack.T119044 - cwe.CWE-9445