Warning: Actively Exploited 0-day vulnerability in CrushFTP, Patch Immediately!
ID: 32d18c0e-dc6b-505d-a28b-de970aac11cb
STIX ID: report--32d18c0e-dc6b-505d-a28b-de970aac11cb
Feed Name: CCB Advisories Feed
CrushFTP disclosed an actively exploited zero-day (CVE-2025-54309, CVSS 9.0) affecting multiple 10.x and 11.x versions that allows unauthenticated remote command execution via a crafted POST to /WebInterface/function/; exploitation was observed in the wild on July 18, 2025. Vendors and CERTs recommend immediate patching to the fixed versions, reviewing uploads/downloads and specific IOCs (e.g., `MainUsers/default/user.XML` last_logins), and heightened monitoring and incident reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
