CVE-2025-31161 is a critical authentication bypass vulnerability affecting CrushFTP versions 10 before 10.8.4 and 11 before 11.3.1, allowing unauthenticated attackers to take over the crushadmin account. This flaw, stemming from a race condition and an index-out-of-bounds error in the AWS4-HMAC authorization method, enables trivial authentication as any known user. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk of full system compromise due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, including in known ransomware campaigns, and has readily available exploit code and significant community discussion, underscoring its immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.8.4CPE matchmatch criteria | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.3.1CPE matchmatch criteria | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* | ||
>= 10, < 10.8.4CPE match | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* | ||
>= 11, < 11.3.1CPE match | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.