CVE-2025-54309

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*
cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*

History

23 Jul 2025, 17:51

Type Values Removed Values Added
CPE cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*
First Time Crushftp crushftp
Crushftp
References () https://www.bleepingcomputer.com/news/security/crushftp-zero-day-exploited-in-attacks-to-gain-admin-access-on-servers/ - () https://www.bleepingcomputer.com/news/security/crushftp-zero-day-exploited-in-attacks-to-gain-admin-access-on-servers/ - Press/Media Coverage
References () https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 - () https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 - Third Party Advisory
References () https://www.rapid7.com/blog/post/crushftp-zero-day-exploited-in-the-wild/ - () https://www.rapid7.com/blog/post/crushftp-zero-day-exploited-in-the-wild/ - Press/Media Coverage

22 Jul 2025, 13:06

Type Values Removed Values Added
Summary
  • (es) CrushFTP 10 anterior a 10.8.5 y 11 anterior a 11.3.4_23, cuando no se utiliza la función de proxy DMZ, maneja incorrectamente la validación AS2 y, en consecuencia, permite a atacantes remotos obtener acceso de administrador a través de HTTPS, como se explotó en la naturaleza en julio de 2025.

19 Jul 2025, 01:15

Type Values Removed Values Added
References
  • () https://www.bleepingcomputer.com/news/security/crushftp-zero-day-exploited-in-attacks-to-gain-admin-access-on-servers/ -
  • () https://www.rapid7.com/blog/post/crushftp-zero-day-exploited-in-the-wild/ -

18 Jul 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-18 19:15

Updated : 2025-07-23 17:51


NVD link : CVE-2025-54309

Mitre link : CVE-2025-54309

CVE.ORG link : CVE-2025-54309


JSON object : View

Products Affected

crushftp

  • crushftp
CWE
CWE-420

Unprotected Alternate Channel