logo

Warning: Critical improper authentication vulnerability in CrushFTP, Patch Immediately!

ID: a37408c0-6cd8-5912-9f35-875014449997

STIX ID: report--a37408c0-6cd8-5912-9f35-875014449997

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
90/100

Date Published: 2025-06-25

Date Updated: 2026-07-24

...
...

CrushFTP versions 10.0.0–10.8.3 and 11.0.0–11.3.0 contain a critical improper authentication vulnerability (CVE-2025-2825 / CVE-2025-31161, CVSS 9.8) that allows unauthenticated remote attackers to gain full administrative access, read and modify host files, and potentially enable lateral movement; a public PoC and Nuclei template exist and there are reports of active exploitation and confirmed ransomware/data exfiltration, so organizations should urgently apply vendor patches (upgrade to 10.8.3 or 11.3.0+) or implement mitigations and increase monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.