Junglewise Threat Intelligence

CVE-2025-54309: CrushFTP unprotected alternate channel in AS2 validation

CVE-2025-54309 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-07-22

Technologies: CrushFTP. Vendors: CrushFTP.

Executive brief

CrushFTP, a popular enterprise file transfer solution, contains a critical vulnerability that allows unauthorized individuals to gain full administrative control over the server. This flaw is particularly dangerous because it can be exploited remotely over the internet without any prior login credentials. Attackers can use this access to steal sensitive files, modify data, or disrupt business operations. This vulnerability has been actively exploited in the wild.

Technical details

CrushFTP versions 10 (prior to 10.8.5) and 11 (prior to 11.3.4_23) are vulnerable to an unprotected alternate channel (CWE-420) flaw. The vulnerability exists in the mishandling of AS2 (Applicability Statement 2) validation when the DMZ proxy feature is not in use. A remote, unauthenticated attacker can exploit this over HTTPS to bypass security controls and gain full administrative privileges. This vulnerability was identified as a zero-day and has been observed in active exploitation. Users are advised to upgrade to the latest patched versions or implement the vendor-recommended DMZ proxy configuration as a mitigation.

Affected products

  • CrushFTP CrushFTP 10 before 10.8.5, 11 before 11.3.4_23

Timeline

  • 2025-07-18: disclosed: Initial CVE entry and vendor advisory published
  • 2025-07-22: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-07-22: advisory: NVD publication date
  • 2025-07-22: exploited: Confirmed active exploitation in the wild

Related threats