PT-2025-30081 · Crushftp · Crushftp
Ben Spink
·
Published
2025-07-18
·
Updated
2025-09-09
·
CVE-2025-54309
9.8
Critical
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
CrushFTP versions prior to 10.8.5 and versions prior to 11.3.4 23
**Description:**
CrushFTP is vulnerable to a critical flaw that allows remote attackers to obtain administrative access via HTTPS when the DMZ proxy feature is not used. This vulnerability arises from improper handling of AS2 validation. Active exploitation of this vulnerability has been observed since July 18, 2025, and it is estimated that over 1,000 servers remain vulnerable. Attackers have been observed hijacking the “crushadmin” account as a backdoor. The vulnerability has a CVSS score of 9.0 and is considered critical due to the potential for complete administrative access.
**Recommendations:**
CrushFTP versions prior to 10.8.5 should be updated.
CrushFTP versions prior to 11.3.4 23 should be updated.
Exploit
Fix
LPE
RCE
Weakness Enumeration
Related Identifiers
Affected Products
References · 199
- 🔥 https://github.com/watchtowrlabs/watchTowr-vs-CrushFTP-Authentication-Bypass-CVE-2025-54309⭐ 15 🔗 1 · Exploit
- https://safe-surf.ru/specialists/bulletins-nkcki/723276 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-54309 · Security Note
- https://crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 · Security Note
- https://bdu.fstec.ru/vul/2025-08775 · Security Note
- https://t.me/cvenotify/129520 · Telegram Post
- https://reddit.com/r/CVEWatch/comments/1n7aq5a/top_10_trending_cves_03092025 · Reddit Post
- https://twitter.com/TweetThreatNews/status/1948307362369929422 · Twitter Post
- https://twitter.com/threatcluster/status/1946483437176762795 · Twitter Post
- https://twitter.com/ggrubamn/status/1947297276306788764 · Twitter Post
- https://twitter.com/liontarakos/status/1961782588508426545 · Twitter Post
- https://twitter.com/pro_recover_y/status/1962509006133465230 · Twitter Post
- https://twitter.com/ASavran8394/status/1955932004354056225 · Twitter Post
- https://twitter.com/watchtowrcyber/status/1960566377808265253 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1947219186301689973 · Twitter Post