CrushFTP CEO's feisty response to VulnCheck's CVE for critical make-me-admin bug
ID: 3d8a390d-418b-5a9a-af28-cc606b3b3c65
STIX ID: report--3d8a390d-418b-5a9a-af28-cc606b3b3c65
Feed Name: The Register (Security)
CrushFTP disclosed a critical unauthenticated access vulnerability affecting multiple versions of its file-transfer software; a third-party CNA published CVE-2025-2825 (CVSS 9.8) and VulnCheck assessed the flaw as remotely exploitable with no authentication and low complexity. The vendor has delayed issuing its own advisory (behind a paywall), sparking a dispute over CVE ownership; while there is no confirmed active exploitation of this specific bug, past CrushFTP zero-days and the high value of file-transfer servers make this a high-risk issue with ransomware and data exfiltration implications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
