ZeroHour

CVE-2025-54309

KEVmoderate

Unauthenticated Admin Access Bypass in CrushFTP (CVE-2025-54309)

CISA: CrushFTP Unprotected Alternate Channel Vulnerability

CVSS 3.1
9.8 critical
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2025-54309 is a critical authentication flaw (CWE-420, an "unprotected alternate channel" issue) in CrushFTP in which AS2 validation is mishandled, allowing unauthenticated HTTPS requests to reach the server's administrative interface through an alternate channel. It is triggered on deployments that do not use the CrushFTP DMZ proxy (perimeter) feature, so any vulnerable instance whose HTTPS service is reachable is exposed; attackers gain full administrative access to the file transfer server and the data it holds. CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23 are affected, while deployments fronted by the DMZ proxy feature are not. The flaw has been exploited in the wild since at least July 18, 2025, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-22, and carries a 94.7% EPSS probability of exploitation within 30 days.

What to do: Upgrade to CrushFTP 10.8.5 (v10 line) or 11.3.4_23 (v11 line) or later; if patching is delayed, enable the DMZ proxy feature or restrict HTTPS access to the server. Because attackers gain admin access, review administrative accounts and HTTPS logs for unexplained activity since at least July 18, 2025, and rotate exposed credentials. Federal agencies must apply vendor mitigations or follow BOD 22-01 guidance, including for cloud service use of the product.

Affected
CrushFTP10 before 10.8.5; 11 before 11.3.4_23 (when the DMZ proxy feature is not used)
Estimated exposure
moderateseveral thousand internet-exposed CrushFTP servers (order of magnitude 10^3–10^4); total deployments likely higher — Public internet-wide scans historically show only on the order of a few thousand CrushFTP instances exposed to the internet, but many more run internally as enterprise managed-file-transfer servers, so the fully affected count (vulnerable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.

CISA Known Exploited Vulnerability
Affected
CrushFTP CrushFTP
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
crushftp
Products
crushftp
Weakness
CWE-420
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news