logo

A Vulnerability in CrushFTP Could Allow for Unauthorized Access

ID: 0c8aa04f-6d54-5e2d-9a3d-fc7e60b4f22a

STIX ID: report--0c8aa04f-6d54-5e2d-9a3d-fc7e60b4f22a

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2025-03-28

Date Updated: 2026-04-27

...
...

A vulnerability in CrushFTP's web interface could allow unauthenticated remote code execution when an HTTP(S) port is exposed; successful exploitation can grant attackers full control of the server (install programs, modify/delete data, create accounts). The report notes the CrushFTP DMZ feature can mitigate the issue but provides no evidence of active exploitation or affected version details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.