CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
References
Link | Resource |
---|---|
https://www.bleepingcomputer.com/news/security/crushftp-zero-day-exploited-in-attacks-to-gain-admin-access-on-servers/ | Press/Media Coverage |
https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 | Third Party Advisory |
https://www.rapid7.com/blog/post/crushftp-zero-day-exploited-in-the-wild/ | Press/Media Coverage |
Configurations
Configuration 1 (hide)
|
History
23 Jul 2025, 17:51
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* | |
First Time |
Crushftp crushftp
Crushftp |
|
References | () https://www.bleepingcomputer.com/news/security/crushftp-zero-day-exploited-in-attacks-to-gain-admin-access-on-servers/ - Press/Media Coverage | |
References | () https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 - Third Party Advisory | |
References | () https://www.rapid7.com/blog/post/crushftp-zero-day-exploited-in-the-wild/ - Press/Media Coverage |
22 Jul 2025, 13:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
19 Jul 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 Jul 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-18 19:15
Updated : 2025-07-23 17:51
NVD link : CVE-2025-54309
Mitre link : CVE-2025-54309
CVE.ORG link : CVE-2025-54309
JSON object : View
Products Affected
crushftp
- crushftp
CWE
CWE-420
Unprotected Alternate Channel