Junglewise Threat Intelligence

CVE-2025-31161: CrushFTP Authentication Bypass Vulnerability

CVE-2025-31161 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-04-07

Technologies: CrushFTP. Vendors: CrushFTP.

Executive brief

CrushFTP contains an authentication bypass vulnerability in its AWS4-HMAC authorization method. A race condition and a subsequent header parsing error allow unauthenticated attackers to bypass authentication for any known user account, potentially leading to full system compromise.

Affected products

  • CrushFTP CrushFTP 10 before 10.8.4, 11 before 11.3.1

Timeline

  • 2025-03: exploited: Exploitation observed in the wild.
  • 2025-04-07: disclosed
  • 2025-04-07: kev added: Added to CISA KEV catalog.

Related threats