CVE-2025-31161CRITICAL 9.8CISA KEVEPSS p100.0%

CVE-2025-31161CrushFTP Authentication Bypass Vulnerability

CrushFTP / CrushFTP

Description

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.96% probability of exploitation · percentile 100.0% · 2026-06-15T12:03:41Z
Published2025-04-03
Last modified2025-10-31

CISA KEV entry

Added to KEV: 2025-04-07

Underlying weaknesses· 1

CWE-305

References

  1. https://crushftp.com/crush11wiki/Wiki.jsp?page=Update#section-Update-VulnerabilityInfo
  2. https://outpost24.com/blog/crushftp-auth-bypass-vulnerability/
  3. https://attackerkb.com/topics/k0EgiL9Psz/cve-2025-2825/rapid7-analysis
  4. https://projectdiscovery.io/blog/crushftp-authentication-bypass
  5. https://www.darkreading.com/vulnerabilities-threats/disclosure-drama-clouds-crushftp-vulnerability-exploitation
  6. https://www.huntress.com/blog/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation
  7. https://www.infosecurity-magazine.com/news/crushftp-flaw-exploited-disclosure/
  8. https://www.vicarius.io/vsociety/posts/cve-2025-31161-detect-crushftp-vulnerability

1

TypeTargetConfidenceTier
WeaknessAuthentication Bypass by Primary Weaknesscwe-3050%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryCrushFTP Authentication Bypass Vulnerabilitykev-cve-2025-311610%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CrushFTP Unprotected Alternate Channel Vulnerability
CVE
CrushFTP VFS Sandbox Escape Vulnerability
CVE
CVE-2025-49195
CVE
CVE-2025-61506
CVE
CVE-2025-69101
CVE
CVE-2025-6979
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.