CVE-2025-54309 is a critical authentication bypass vulnerability affecting CrushFTP versions 10 (before 10.8.5) and 11 (before 11.3.4_23) when the DMZ proxy is not in use. This flaw, stemming from improper AS2 validation, allows unauthenticated remote attackers to gain administrative access over HTTPS. With a CVSS score of 9.8 (CRITICAL), it requires no user interaction or complex conditions for exploitation, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog and extensive community discussion, including multiple media reports detailing ongoing attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.8.5CPE matchmatch criteria | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.3.4_23CPE matchmatch criteria | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* | ||
>= 10, < 10.8.5CPE match | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* | ||
>= 11, < 11.3.4_23CPE match | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.