CrushFTP Authentication Bypass Attack
ID: a897e071-f10c-55f4-9c35-8e57f898273b
STIX ID: report--a897e071-f10c-55f4-9c35-8e57f898273b
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
FortiGuard Labs reports active and persistent exploitation attempts targeting CVE-2025-31161, an authentication-bypass vulnerability in CrushFTP that can grant administrative access. A public proof-of-concept is available, affected versions include 10.0.0–10.8.3 and 11.0.0–11.3.0, and users are advised to upgrade to 10.8.4 or 11.3.1+ immediately to mitigate risk; the advisory warns of likely rapid adoption by threat actors including ransomware groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
