logo

CrushFTP Security Vulnerability Under Attack After PoC Release

ID: f019e744-4b2c-5baf-9c2d-55b814d5b158

STIX ID: report--f019e744-4b2c-5baf-9c2d-55b814d5b158

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2025-04-01

Date Updated: 2026-04-22

Author: Divya

...
...

A critical remote code execution vulnerability in CrushFTP (CVE-2025-2825) is being actively exploited following release of a public proof-of-concept; Shadowserver reports exploitation attempts and about 1,512 unpatched instances exposed, creating a significant risk of unauthorized access, data breaches, and full server compromise — administrators are urged to apply patches, monitor logs, restrict access, and enable alerts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.