CVE-2025-54309
KEVmoderateUnauthenticated Admin Access Bypass in CrushFTP (CVE-2025-54309)
CISA: CrushFTP Unprotected Alternate Channel Vulnerability
CVE-2025-54309 is a critical authentication flaw (CWE-420, an "unprotected alternate channel" issue) in CrushFTP in which AS2 validation is mishandled, allowing unauthenticated HTTPS requests to reach the server's administrative interface through an alternate channel. It is triggered on deployments that do not use the CrushFTP DMZ proxy (perimeter) feature, so any vulnerable instance whose HTTPS service is reachable is exposed; attackers gain full administrative access to the file transfer server and the data it holds. CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23 are affected, while deployments fronted by the DMZ proxy feature are not. The flaw has been exploited in the wild since at least July 18, 2025, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-22, and carries a 94.7% EPSS probability of exploitation within 30 days.
What to do: Upgrade to CrushFTP 10.8.5 (v10 line) or 11.3.4_23 (v11 line) or later; if patching is delayed, enable the DMZ proxy feature or restrict HTTPS access to the server. Because attackers gain admin access, review administrative accounts and HTTPS logs for unexplained activity since at least July 18, 2025, and rotate exposed credentials. Federal agencies must apply vendor mitigations or follow BOD 22-01 guidance, including for cloud service use of the product.
| CrushFTP | 10 before 10.8.5; 11 before 11.3.4_23 (when the DMZ proxy feature is not used) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
- Affected
- CrushFTP CrushFTP
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- crushftp
- Products
- crushftp
- Weakness
- CWE-420
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H