CrushFTP
cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*
- < 10.8.5
- < 11.3.4_23
This vulnerability is being actively exploited in the wild.
A vulnerability in CrushFTP versions 10 prior to 10.8.5 and 11 prior to 11.3.4_23, when the DMZ proxy feature is not utilized, improperly manages AS2 validation. This flaw enables remote attackers to gain administrative access via HTTPS. The issue was actively exploited in July 2025.
Exploitation of this vulnerability allows remote attackers to obtain administrative access on the affected CrushFTP server.
Users can restore a compromised default admin user by retrieving it from a backup made before the exploit occurred. This backup is located in the CrushFTP folder under 'users/MainUsers/default'. However, it's important to note that these zip files cannot be extracted with the native Windows unzip tool; programs like WinRAR, macOS's Archive Utility, or WinZip are required. Alternatively, the default user can be deleted, prompting CrushFTP to recreate it, although this method will not preserve any customizations.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.