logo

First Look at CVE-2025-54309: Dissecting the Latest CrushFTP Exploit

ID: cd9166b1-cdcf-50a0-b9c9-4ca87da40cd1

STIX ID: report--cd9166b1-cdcf-50a0-b9c9-4ca87da40cd1

Feed Name: ReliaQuest Blog

Threat Score
80/100

Date Published: 2025-07-28

Date Updated: 2026-04-29

...
...

ReliaQuest analyzed active exploitation of a zero-day in CrushFTP (CVE-2025-54309) where attackers abused weak AS2 validation—an unprotected alternative communication channel—to bypass primary authentication, gain administrative access, enumerate directories, and attempt to overwrite the default user to create a persistent backdoor; IP allowlists and policy restrictions prevented full compromise and CrushFTP has released a patch and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.