CrushFTP Vulnerability Exploited in Attacks Following PoC Release
ID: 758b4134-735e-510a-86d5-19d0392ee520
STIX ID: report--758b4134-735e-510a-86d5-19d0392ee520
Feed Name: cybersecurityNews.com
Security researchers and Shadowserver report active exploitation of a critical CrushFTP authentication bypass (CVE-2025-2825, CVSS 9.8) following public PoC release; approximately 1,512 unpatched instances remain worldwide (majority in North America). The exploit uses a spoofed AWS header, a crafted 44-character CrushAuth cookie, and c2f parameter manipulation to bypass authentication and potentially allow full system compromise; CrushFTP released patches (11.3.1 / 10.8.4) and vendors and analysts recommend immediate patching, DMZ as temporary mitigation, log auditing, and use of detection tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
