PT-2025-14099 · Crushftp · Crushftp

·

CVE-2025-31161

·

Published

2025-03-13

·

Updated

2026-08-31

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CrushFTP versions 10.0.0 through 10.8.3 CrushFTP versions 11.0.0 through 11.3.0
Description An authentication bypass exists in the HTTP component of the FTP server, specifically within the AWS4-HMAC (S3 compatible) authorization method. The issue stems from a race condition where the server verifies user existence via the login user pass() function without requiring a password, temporarily authenticating the session. This can be stabilized by sending a mangled AWS4-HMAC header containing only a username followed by a slash (/), which triggers an anypass authentication process. The subsequent failure to find the SignedHeaders entry causes an index-out-of-bounds error, preventing session cleanup and allowing an attacker to authenticate as any known user, such as crushadmin. This flaw has been exploited in the wild since March 2025, affecting sectors including retail, marketing, and semiconductors, with approximately 130,000 instances estimated to be exposed online. Attackers have used the setUserItem function to create backdoor administrative accounts and deployed tools like MeshCentral, AnyDesk, and Telegram bot DLLs to maintain persistence and collect telemetry.
Recommendations Update CrushFTP version 10 to 10.8.4. Update CrushFTP version 11 to 11.3.1. Use a DMZ proxy instance as a temporary buffer to mitigate the risk of authentication bypass.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03886
CVE-2025-31161

Affected Products

Crushftp