CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
References
Configurations
Configuration 1 (hide)
|
History
21 Oct 2025, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:21
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
25 Sep 2025, 18:03
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 - Vendor Advisory | |
| References | () https://www.vicarius.io/vsociety/posts/cve-2025-54309-detect-crushftp-vulnerability - Third Party Advisory | |
| References | () https://www.vicarius.io/vsociety/posts/cve-2025-54309-mitigate-crushftp-vulnerability - Third Party Advisory |
25 Sep 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
23 Jul 2025, 17:51
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.bleepingcomputer.com/news/security/crushftp-zero-day-exploited-in-attacks-to-gain-admin-access-on-servers/ - Press/Media Coverage | |
| References | () https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 - Third Party Advisory | |
| References | () https://www.rapid7.com/blog/post/crushftp-zero-day-exploited-in-the-wild/ - Press/Media Coverage | |
| CPE | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* | |
| First Time |
Crushftp crushftp
Crushftp |
22 Jul 2025, 13:06
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
19 Jul 2025, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
18 Jul 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-07-18 19:15
Updated : 2025-10-21 23:17
NVD link : CVE-2025-54309
Mitre link : CVE-2025-54309
CVE.ORG link : CVE-2025-54309
JSON object : View
Products Affected
crushftp
- crushftp
CWE
CWE-420
Unprotected Alternate Channel
