CVE-2025-54309CRITICAL 9.8CISA KEVEPSS p99.8%
CVE-2025-54309 CrushFTP Unprotected Alternate Channel Vulnerability
CrushFTP / CrushFTP
Description
CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 92.03% probability of exploitation · percentile 99.8% · 2026-06-18T12:00:27Z |
| Published | 2025-07-18 |
| Last modified | 2025-11-05 |
CISA KEV entry
Added to KEV: 2025-07-22
Underlying weaknesses· 1
References
- https://www.bleepingcomputer.com/news/security/crushftp-zero-day-exploited-in-attacks-to-gain-admin-access-on-servers/
- https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025
- https://www.rapid7.com/blog/post/crushftp-zero-day-exploited-in-the-wild/
- https://www.vicarius.io/vsociety/posts/cve-2025-54309-detect-crushftp-vulnerability
- https://www.vicarius.io/vsociety/posts/cve-2025-54309-mitigate-crushftp-vulnerability
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-54309
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Unprotected Alternate Channelcwe-420 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | CrushFTP Unprotected Alternate Channel Vulnerabilitykev-cve-2025-54309 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.