CVE-2025-54309

9.5 CISA KEV

CrushFTP · CrushFTP

CrushFTP versions 10 and 11 contain an unprotected alternate channel vulnerability where improper AS2 validation allows unauthenticated remote attackers to gain administrative access via HTTPS.

Executive summary

This critical vulnerability in CrushFTP is being actively exploited in the wild to grant attackers unauthorized administrative access to affected servers.

Vulnerability

The flaw originates from improper AS2 validation when the DMZ proxy feature is not utilized. This allows an unauthenticated remote attacker to bypass security controls and obtain administrative privileges over the application.

Business impact

With a CVSS score of 9.5, this vulnerability represents a critical risk to organizational data and infrastructure. Successful exploitation allows an attacker to achieve full administrative control, potentially leading to total system compromise, data exfiltration, and unauthorized execution of commands. The immediate availability of public proof-of-concept code significantly lowers the barrier for exploitation by malicious actors.

Remediation

Immediate Action: Upgrade to CrushFTP version 10.8.5 or 11.3.4_23 (or later versions like 10.8.5_12 and 11.3.4_26) immediately to apply the necessary security patches.

Proactive Monitoring: Monitor server logs for unauthorized administrative logins or suspicious outbound connections originating from the CrushFTP service.

Compensating Controls: If immediate patching is not feasible, ensure the DMZ proxy feature is properly configured and enabled, as the vulnerability specifically impacts instances where this feature is absent or bypassed.

Exploitation status

Public Exploit Available: Yes, multiple public proofs-of-concept are available via GitHub repositories.

Analyst recommendation

Due to confirmed active exploitation in the wild and the severity of the access granted, organizations running affected versions of CrushFTP must prioritize patching above all other maintenance tasks. If the software cannot be updated, it should be isolated from the public internet immediately to prevent further exploitation.

Sources