ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Critical CrushFTP vulnerability exploited. Have you been targeted? (CVE-2025-54309)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-4040
Unauthenticated Sandbox Escape and RCE in CrushFTP (CVE-2024-4040)

CrushFTP contains a server-side template injection flaw (CWE-94, CWE-1336) that allows unauthenticated remote attackers to escape the Virtual File System (VFS) sandbox. The flaw is triggered by unauthenticated network requests to any CrushFTP server running versions before 10.7.1 or 11.1.0 on any platform. Successful exploitation lets an attacker read files from the filesystem outside the VFS sandbox, bypass authentication to gain administrative access, and execute arbitrary code on the server. All CrushFTP deployments on prior versions are affected, especially internet-exposed file transfer servers. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-24, EPSS puts 30-day exploitation probability at 99.5%, and public scans have identified at least 1,400 vulnerable exposed servers.

Do: Upgrade immediately to CrushFTP 10.7.1 (10.x line) or 11.1.0 (11.x line) or later, as the vendor has urged, or apply the vendor's documented mitigations if patching is delayed. Prioritize internet-facing instances, and check them for signs of compromise such as unauthorized administrative access or unexpected file reads. Public proof-of-concept code exists, so assume unpatched exposed servers will be exploited.

10.0100% KEV PoC ×2
  • CrushFTP All versions before 10.7.1 and 11.1.0, on all platforms
moderate≈1,400+ internet-exposed CrushFTP servers (public scan count), likely more including internal-only deployments
CVE-2025-2825
Rejected reason: DO NOT USE THIS CVE RECORD.

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-31161. Reason: This Record is a reservation duplicate of CVE-2025-31161. Notes: All CVE users should reference CVE-2025-31161 instead of this Record. All references and descriptions in this Record have been removed to prevent accidental usage.

NVD description · AI analysis pending
CVE-2025-54309
Unauthenticated Admin Access Bypass in CrushFTP (CVE-2025-54309)

CVE-2025-54309 is a critical authentication flaw (CWE-420, an "unprotected alternate channel" issue) in CrushFTP in which AS2 validation is mishandled, allowing unauthenticated HTTPS requests to reach the server's administrative interface through an alternate channel. It is triggered on deployments that do not use the CrushFTP DMZ proxy (perimeter) feature, so any vulnerable instance whose HTTPS service is reachable is exposed; attackers gain full administrative access to the file transfer server and the data it holds. CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23 are affected, while deployments fronted by the DMZ proxy feature are not. The flaw has been exploited in the wild since at least July 18, 2025, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-22, and carries a 94.7% EPSS probability of exploitation within 30 days.

Do: Upgrade to CrushFTP 10.8.5 (v10 line) or 11.3.4_23 (v11 line) or later; if patching is delayed, enable the DMZ proxy feature or restrict HTTPS access to the server. Because attackers gain admin access, review administrative accounts and HTTPS logs for unexplained activity since at least July 18, 2025, and rotate exposed credentials. Federal agencies must apply vendor mitigations or follow BOD 22-01 guidance, including for cloud service use of the product.

9.895% KEV
  • CrushFTP 10 before 10.8.5; 11 before 11.3.4_23 (when the DMZ proxy feature is not used)
moderateseveral thousand internet-exposed CrushFTP servers (order of magnitude 10^3–10^4); total deployments likely higher
Full article390 words · extracted from helpnetsecurity.com · click to collapse

Unknown attackers have exploited a vulnerability (CVE-2025‑54309) in the CrushFTP enterprise file-transfer server solution to gain administrative access to vulnerable deployments.

CrushFTP CVE-2025‑54309 vulnerability exploited

It’s currently unclear what the attackers are using this access for, but data theft looks most likely.

According to the Shadowserver Foundation, there are currently around 1,040 exposed and unpatched CrushFTP instances vulnerable to CVE-2025-54309, predominantly located in the US, Europe, and Canada.

How many have been compromised since the attacks began is difficult to know for sure. Organizations that use CrushFTP and haven’t upgraded their instance(s) lately should check whether they have been breached.

About CVE-2025‑54309

On Friday (July 18), the CrushFTP team warned about attackers using a 0-day exploit, after apparently reverse engineering a recent update and discovering a bug that the maintainers had already fixed.

CVE-2025-54309 stems from CrushFTP mishandling the validation of Applicability Statement 2 (AS2) and allows remote, unauthenticated attackers to obtain admin access to exposed CrushFTP web interfaces via HTTPS.

“We believe this bug was in builds prior to July 1st time period roughly…the latest versions of CrushFTP already have the issue patched,” the maintainers said.

“We had fixed a different issue related to AS2 in HTTP(S) not realizing that prior bug could be used like this exploit was.”

CVE-2025-54309 affects:

  • CrushFTP 10 prior to v10.8.5
  • CrushFTP 11 prior to v11.3.4_23

What should you do?

Organizations that use CrushFTP and have upgraded to the most recent available version soon after it has been made available have likely not been breached.

According to the maintainers, “enterprise customers with a DMZ CrushFTP in front of their main [instance]” have also not been affected by the exploit, though Rapid7 researchers say customers shouldn’t count on a demilitarized zone (DMZ) as a mitigation strategy.

CrushFTP developers have outlined indicators of compromise enterprises should look for when checking whether their instance(s) have been successfully targeted, advice on what to do if they find out they’ve been affected, and advice on how to minimize the risk of their instances getting compromised in the future.

Since April 2024, attackers have exploited two vulnerabilities in CrushFTP (CVE-2024-4040 and CVE-2025-2825), as well as zero and n-day vulnerabilities in other popular file transfer solutions used by businesses.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/07/21/crushftp-cve-2025-54309-vulnerability-exploited/