Following indications of active exploitation in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a recently discovered critical security weakness affecting CrushFTP to its Known Exploited Vulnerabilities (KEV) list.
An unauthenticated attacker could take control of vulnerable instances due to the vulnerability, which is a case of authentication bypass. Versions 10.8.4 and 11.3.1 have fixed it.
A remote, unauthenticated attacker might authenticate to any known or guessable user account (such as crushadmin) using CrushFTP’s authentication bypass vulnerability in the HTTP permission header, which could result in a complete compromise, according to a CISA advisory.
The CVE number for the vulnerability is CVE-2025-31161 (CVSS score: 9.8). It is important to remember that the same weakness existed previously read more about CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active Exploitation.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
