ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

CISA Warns of CrushFTP Vulnerability Exploitation in the Wild

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-31161CVE-2025-2825CVE-2024-2825

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-2825
A vulnerability classified as critical has been found in lakernote EasyAdmin up to 20240315.

A vulnerability classified as critical has been found in lakernote EasyAdmin up to 20240315. This affects an unknown part of the file /ureport/designer/saveReportFile. The manipulation of the argument file leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257715.

NVD description · AI analysis pending
8.8<1% PoC
  • lakernote easyadmin
CVE-2025-2825
Rejected reason: DO NOT USE THIS CVE RECORD.

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-31161. Reason: This Record is a reservation duplicate of CVE-2025-31161. Notes: All CVE users should reference CVE-2025-31161 instead of this Record. All references and descriptions in this Record have been removed to prevent accidental usage.

NVD description · AI analysis pending
CVE-2025-31161
Authentication Bypass in CrushFTP File Transfer Servers (CVE-2025-31161)

CrushFTP contains an authentication bypass (CWE-305) in its handling of the HTTP authorization header, allowing crafted header values to grant access without valid credentials. A remote, unauthenticated attacker who can reach the server's HTTP/HTTPS interface can use this flaw to authenticate as any known or guessable account, such as the built-in crushadmin user. With administrative access, the attacker can typically achieve full compromise of the file-transfer server, including access to hosted files and user accounts. Any organization running CrushFTP is affected, with internet-exposed instances at the highest risk. The flaw is being actively exploited: it was added to CISA's KEV on 2025-04-07 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Upgrade to the vendor's fixed releases (10.8.0 for the 10.x line and 11.3.1 for the 11.x line, per vendor advisories); federal agencies must follow BOD 22-01 timelines or discontinue use if mitigations are unavailable. Until patched, restrict network access to the CrushFTP HTTP/HTTPS interface and audit authentication logs for unexpected logins to privileged accounts such as crushadmin. Given confirmed ransomware use, treat internet-exposed instances as actively targeted and verify there are no signs of prior compromise after patching.

9.8100% KEV ransomware PoC ×4
  • CrushFTP
moderate≈5,000–10,000 internet-exposed CrushFTP servers (public scan counts), with additional uncounted internal enterprise deployments
Full article414 words · extracted from infosecurity-magazine.com · click to collapse

The US top cybersecurity agency has confirmed that the critical vulnerability in file transfer solution provider CrushFTP’s product is being exploited in the wild.

The authentication bypass vulnerability, CVE-2025-31161, was added to the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog on April 7.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” said the security advisory.

CISA strongly urged all federal departments and other organizations to prioritize remediating the vulnerability as part of their vulnerability management practice.

Vulnerability Disclosure Mix-Up

The vulnerability is a critical authentication bypass (CVSS base score of 9.8) that could allow an unauthenticated actor to take over devices running unpatched versions of CrushFTP v10 or v11.

It was identified by Outpost24 and disclosed by CrushFTP on March 21 and has been fixed in versions 10.8.4 and 11.3.1.

However, the vulnerability experienced a disclosure mix-up with two separate vulnerability identifiers published by two CVE Numbering Authorities (CNAs) relating to the same issue.

Outpost24 worked with MITRE, a CNA, to secure CVE identifier CVE-2025-31161.

Outpost24 and MITRE then coordinated with CrushFTP to agree on a 90-day non-disclosure period to ensure users had sufficient time to patch before details became public.

Meanwhile, another CNA, VulnCheck, published a separate identifier, CVE-2025-2825, on March 26, allegedly without consulting Outpost24 or CrushFTP.

Two days later, the Shadowserver Foundation said on X that it was observing exploitation attempts of CVE-2025-2825 based on a publicly available proof-of-concept (PoC) exploit code. The non-profit also identified at least 1512 unpatched instances vulnerable to CVE-2025-2825.

— The Shadowserver Foundation (@Shadowserver) March 31, 2025

MITRE published the CVE-2025-31161 entry on April 3. The CVE-2025-2825 now appears as ‘Rejected’ on MITRE’s website and the US National Vulnerability Database (NVD).

Outpost24 argued in an April 2 security update that the VulnCheck disclosure led to the vulnerability becoming widely known before users could update their systems, resulting in active exploitation.

On the other hand, VulnCheck criticized MITRE for rejecting CVE-2024-2825.

Disclosure and exploitation timeline for the latest CrushFTP vulnerability. Source: VulnCheck
Disclosure and exploitation timeline for the latest CrushFTP vulnerability. Source: VulnCheck

“CrushFTP […] deliberately requested that a CVE not be issued for 90 days, effectively trying to hide the vulnerability from the security community and defenders,” Patrick Garrity, Security Researcher at VulnCheck, said on LinkedIn.

“What’s worse is that MITRE appears to have prioritized their involvement in the write-up over the timely disclosure of a vulnerability actively exploited in the wild... This sets a dangerous precedent,” he added.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/crushftp-vulnerability-cisa-kev/