logo

CrushFTP Vulnerability Exploited to Gain Full Server Access

ID: 658e03f5-c889-5501-b713-d59f101c9502

STIX ID: report--658e03f5-c889-5501-b713-d59f101c9502

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-03-31

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A critical authentication bypass (CVE-2025-2825, CVSS 9.8) in CrushFTP’s Amazon S3-compatible API lets attackers bypass password checks by exploiting parameter overloading (lookup_user_pass / anyPass). A proof-of-concept was published and ProjectDiscovery released a Nuclei template; CrushFTP patched the issue in version 11.3.1 and organizations are advised to update immediately or apply temporary mitigations such as enabling the DMZ feature and network-level access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.