PT-2025-30081 · Crushftp · Crushftp
Ben Spink
·
Published
2025-07-18
·
Updated
2025-07-21
·
CVE-2025-54309
9.0
Critical
Base vector | Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
CrushFTP versions prior to 10.8.5 and versions prior to 11.3.4 23
**Description:**
CrushFTP is affected by a zero-day vulnerability that allows remote attackers to obtain admin access via HTTPS when the DMZ proxy feature is not used. This issue is due to improper handling of AS2 validation. The vulnerability has been actively exploited in the wild since July 18, 2025. Approximately 291,903 devices running CrushFTP are estimated to be exposed. Compromised instances may lead to data theft and the installation of backdoors.
**Recommendations:**
CrushFTP versions prior to 10.8.5: Update to version 10.8.5 or later.
CrushFTP versions prior to 11.3.4 23: Update to version 11.3.4 23 or later.
Fix
Weakness Enumeration
Related Identifiers
Affected Products
References · 72
- https://bdu.fstec.ru/vul/2025-08775 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-54309 · Security Note
- https://twitter.com/news_24_365/status/1946866312241942757 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1947219186301689973 · Twitter Post
- https://twitter.com/secured_cyber/status/1947321242899579016 · Twitter Post
- https://twitter.com/ransomnews/status/1946569213302227209 · Twitter Post
- https://t.me/c/2230009192/28166 · Telegram Post
- https://twitter.com/shah_sheikh/status/1946861226874515945 · Twitter Post
- https://twitter.com/CyberVenom01/status/1947064761377522085 · Twitter Post
- https://twitter.com/HAF_tech/status/1946908014541234364 · Twitter Post
- https://twitter.com/wvipersg/status/1947221044579664192 · Twitter Post
- https://bleepingcomputer.com/news/security/new-crushftp-zero-day-exploited-in-attacks-to-hijack-servers · Note
- https://twitter.com/Trej0Jass/status/1946836510768316881 · Twitter Post
- https://twitter.com/ScyScan/status/1947376080157086090 · Twitter Post
- https://twitter.com/RedLegg/status/1947423027358028023 · Twitter Post