CrushFTP Vulnerability Exploited to Gain Full Server Access
ID: 658e03f5-c889-5501-b713-d59f101c9502
STIX ID: report--658e03f5-c889-5501-b713-d59f101c9502
Feed Name: cybersecurityNews.com
Threat Score
A critical authentication bypass (CVE-2025-2825, CVSS 9.8) in CrushFTP’s Amazon S3-compatible API lets attackers bypass password checks by exploiting parameter overloading (lookup_user_pass / anyPass). A proof-of-concept was published and ProjectDiscovery released a Nuclei template; CrushFTP patched the issue in version 11.3.1 and organizations are advised to update immediately or apply temporary mitigations such as enabling the DMZ feature and network-level access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
