CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2025-54309

CVSS 9.0v3.1pub. 2025-07-18upd. 2025-11-05

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.

🤖 AI Analysis
How it works

When the DMZ proxy feature is not in use, the CrushFTP server improperly handles the AS2 validation process (CWE-420 – unsecured alternate channel for access). A remote attacker, without any authentication and without user interaction, can send a specially crafted HTTPS request that bypasses access control mechanisms. As a result, they obtain administrative privileges on the server.

Impact

An attacker can gain full administrative control over the CrushFTP server, including access to stored files, system configuration, and the ability to further compromise the organization's infrastructure.

Mitigation & patch

CrushFTP must be immediately updated to version 10.8.5 or newer (branch 10) or to version 11.3.4_23 or newer (branch 11). As a temporary workaround, the vendor recommends enabling the DMZ proxy feature, which blocks the attack vector. Please consult the vendor's official statement available at crushftp.com.

Who is affected

CrushFTP version 10 before 10.8.5 and CrushFTP version 11 before 11.3.4_23, when the DMZ proxy feature is not configured and active.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Crushftp

    APP
    Crushftp
    10.0.0 – 10.8.5 (excl.)11.0.0 – 11.3.4_23 (excl.)

CISA KEV — detailsi

Vendori
CrushFTP
Producti
CrushFTP
Added to KEVi
July 22, 2025
Remediation deadline (US Federal)i
August 12, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 12 sierpnia 2025
CWE
References

Related vulnerabilities

CVE-2025-31161CRITICAL9.8⚠ KEVPL ✓same product

CrushFTP – pominięcie uwierzytelnienia i przejęcie konta administratora

CVE-2024-4040CRITICAL9.8⚠ KEVPL ✓same product

Server Side Template Injection w CrushFTP — RCE bez uwierzytelnienia

CVE-2024-53552CRITICAL9.8PL ✓same product

CrushFTP: Przejęcie konta przez błąd w resetowaniu hasła

CVE-2023-43177CRITICAL9.8PL ✓same product

CrushFTP – krytyczna podatność na manipulację atrybutami obiektów (przed wersją 10.5.1)

CVE-2017-14035CRITICAL9.8PL ✓same product

CrushFTP 8.x — podatność deserializacji umożliwiająca RCE