CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
When the DMZ proxy feature is not in use, the CrushFTP server improperly handles the AS2 validation process (CWE-420 – unsecured alternate channel for access). A remote attacker, without any authentication and without user interaction, can send a specially crafted HTTPS request that bypasses access control mechanisms. As a result, they obtain administrative privileges on the server.
An attacker can gain full administrative control over the CrushFTP server, including access to stored files, system configuration, and the ability to further compromise the organization's infrastructure.
CrushFTP must be immediately updated to version 10.8.5 or newer (branch 10) or to version 11.3.4_23 or newer (branch 11). As a temporary workaround, the vendor recommends enabling the DMZ proxy feature, which blocks the attack vector. Please consult the vendor's official statement available at crushftp.com.
CrushFTP version 10 before 10.8.5 and CrushFTP version 11 before 11.3.4_23, when the DMZ proxy feature is not configured and active.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HCrushftp
APPCrushftp10.0.0 – 10.8.5 (excl.)11.0.0 – 11.3.4_23 (excl.)
CISA KEV — detailsi
- Vendori
- CrushFTP
- Producti
- CrushFTP
- Added to KEVi
- July 22, 2025
- Remediation deadline (US Federal)i
- August 12, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.
Related vulnerabilities
CrushFTP – pominięcie uwierzytelnienia i przejęcie konta administratora
Server Side Template Injection w CrushFTP — RCE bez uwierzytelnienia
CrushFTP: Przejęcie konta przez błąd w resetowaniu hasła
CrushFTP – krytyczna podatność na manipulację atrybutami obiektów (przed wersją 10.5.1)
CrushFTP 8.x — podatność deserializacji umożliwiająca RCE