Executive brief
CrushFTP contains an authentication bypass vulnerability in its AWS4-HMAC authorization method. A race condition and a subsequent header parsing error allow unauthenticated attackers to bypass authentication for any known user account, potentially leading to full system compromise.
Affected products
- CrushFTP CrushFTP 10 before 10.8.4, 11 before 11.3.1
Timeline
- 2025-03: exploited: Exploitation observed in the wild.
- 2025-04-07: disclosed
- 2025-04-07: kev added: Added to CISA KEV catalog.