Tag: CrushFTP file transfer

Critical auth bypass bug in CrushFTP now exploited in attacks
News

Critical auth bypass bug in CrushFTP now exploited in attacks

Attackers are now utilizing exploits based on publicly accessible proof-of-concept code to attack a significant authentication bypass vulnerability in the CrushFTP file transfer program. Outpost24 discovered the security flaw (CVE-2025-2825), which enables remote attackers to access devices running unpatched CrushFTP v10 or v11 software without authorization. Please act right away to patch as soon as possible. When CrushFTP issued fixes to fix the security problem on Friday, March 21, it sent out an email to its clients warning that an unprotected HTTP(S) port could result in unauthenticated access. Administrators who are unable to update CrushFTP 10.8.4 or 11.3.1 right away can use the DMZ (demilitarized zone) perimeter network option as a workaround to safeguard their CrushFTP ...