grep -l "Sudo" ./machines (2)

WingData [Linux]
Easy
Unauthenticated RCE in Wing FTP Server v7.4.3 via NULL byte Lua injection (CVE-2025-47812), lateral movement through cracked FTP user password hash, and root via Python tarfile data filter PATH_MAX bypass (CVE-2025-4517).
Wing FTP ServerCVE-2025-47812Lua injectionpassword crackinghashcattarfile filter bypass +3
โ— pwned
Expressway [Linux]
Easy
IKEv1 Aggressive Mode PSK hash capture and offline brute-force reveals SSH credentials; custom sudo 1.9.17 binary is exploited via CVE-2025-32463 NSS library injection to achieve root.
ikeikev1aggressive-modepskipsecsudo +3
โ— pwned