logo

CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation

ID: a83deb48-cc8c-59fd-8309-0a255ed8d11f

STIX ID: report--a83deb48-cc8c-59fd-8309-0a255ed8d11f

Feed Name: Huntress Blog

Threat Score
88/100

Date Published: 2025-04-04

Date Updated: 2026-04-28

...
...

**Executive Summary:** Huntress documents active exploitation of CVE-2025-31161, a critical authentication bypass in CrushFTP (affecting versions 10.0.0–10.8.3 and 11.0.0–11.3.0), demonstrates a simple HTTP-based PoC, and provides observed post-exploitation tradecraft where attackers deployed RMM tools (MeshAgent, AnyDesk, SimpleHelp), performed credential harvesting and persistence, and uploaded a Telegram-based DLL; the report includes IOCs and recommends immediate patching and detection measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.