CVE-2025-54309

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*
cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*

History

23 Jul 2025, 17:51

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Crushftp
Crushftp crushftp
CPE cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*
References () https://www.bleepingcomputer.com/news/security/crushftp-zero-day-exploited-in-attacks-to-gain-admin-access-on-servers/ - () https://www.bleepingcomputer.com/news/security/crushftp-zero-day-exploited-in-attacks-to-gain-admin-access-on-servers/ - Press/Media Coverage
References () https://www.rapid7.com/blog/post/crushftp-zero-day-exploited-in-the-wild/ - () https://www.rapid7.com/blog/post/crushftp-zero-day-exploited-in-the-wild/ - Press/Media Coverage
References () https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 - () https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 - Third Party Advisory

19 Jul 2025, 01:15

Type Values Removed Values Added
CWE CWE-420
References
  • () https://www.bleepingcomputer.com/news/security/crushftp-zero-day-exploited-in-attacks-to-gain-admin-access-on-servers/ -
  • () https://www.rapid7.com/blog/post/crushftp-zero-day-exploited-in-the-wild/ -

18 Jul 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-18 19:15

Updated : 2025-07-23 17:51


NVD link : CVE-2025-54309

Mitre link : CVE-2025-54309


JSON object : View

Products Affected

crushftp

  • crushftp
CWE

No CWE.