CVE-2025-54309
18.07.2025, 19:15
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.Enginsight
| Vendor | Product | Version |
|---|---|---|
| crushftp | crushftp | 10.0.0 ≤ 𝑥 < 10.8.5 |
| crushftp | crushftp | 11.0.0 ≤ 𝑥 < 11.3.4_23 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References