Disclosure Drama Clouds CrushFTP Vulnerability Exploitation
ID: 95327f5b-dfc8-5470-9915-275f301d48e1
STIX ID: report--95327f5b-dfc8-5470-9915-275f301d48e1
Feed Name: Dark Reading
A critical authentication-bypass vulnerability in CrushFTP was disclosed and quickly weaponized after conflicting CVE assignments and public analyses published proof-of-concept exploits; Shadowserver detected 1,512 vulnerable instances and vendors reported customer compromises. The report details the disclosure timeline, disputes between CrushFTP, VulnCheck, Outpost24 and others, technical write-ups from ProjectDiscovery and Rapid7 that included PoCs, and mitigation guidance (update to CrushFTP 11.3.1 or enable DMZ) while noting ongoing exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
