URGENT: Critical CrushFTP Auth Bypass Vulnerability Now Under Active Attack


# Critical Vulnerability in CrushFTP Software Under Active Exploitation

Attackers are actively targeting a critical authentication bypass vulnerability in CrushFTP file transfer software, leveraging publicly available proof-of-concept code. The vulnerability (CVE-2025-2825), discovered by Outpost24, allows remote attackers to gain unauthorized access to systems running unpatched CrushFTP v10 or v11.

“Please take immediate action to patch ASAP. The bottom line of this vulnerability is that an exposed HTTP(S) port could lead to unauthenticated access,” CrushFTP warned customers on March 21 when releasing patches for the security flaw.

Administrators unable to immediately update to CrushFTP 10.8.4+ or 11.3.1+ can temporarily enable the DMZ (demilitarized zone) perimeter network option as a protective measure.

One week after the patch release, Shadowserver reported detecting numerous exploitation attempts targeting internet-exposed CrushFTP servers. Their monitoring revealed over 1,500 vulnerable instances still accessible online as of March 30. This surge in attacks followed ProjectDiscovery’s publication of technical details and a proof-of-concept exploit for CVE-2025-2825.

File transfer products like CrushFTP are prime targets for ransomware groups, particularly the Clop gang, which has previously exploited zero-day vulnerabilities in similar platforms including Accelion FTA, MOVEit Transfer, GoAnywhere MFT, and Cleo software.

This isn’t the first critical vulnerability for CrushFTP. In April 2024, the company patched an actively exploited zero-day (CVE-2024-4040) that allowed attackers to escape the virtual file system and download system files. CrowdStrike linked that campaign to politically motivated intelligence-gathering operations targeting U.S. organizations. The Cybersecurity and Infrastructure Security Agency (CISA) subsequently added this vulnerability to its Known Exploited Vulnerabilities catalog.

CrushFTP users were also previously warned about a critical remote code execution vulnerability (CVE-2023-43177) in November 2023, which saw a proof-of-concept exploit released three months after security updates became available.

Share This Article