Main
Vulnerability Database
Exploits
ID:11957 - Exploit for Improper authentication in CrushFTP - CVE-2025-54309
ID:11957 - Exploit for Improper authentication in CrushFTP - CVE-2025-54309
Published: September 12, 2025
Vulnerability identifier: #VU113076
Vulnerability risk: Critical
CVE-ID: CVE-2025-54309
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
CrushFTP
CrushFTP
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to improper input validation in AS2 file transfer protocol. A remote attacker can obtain the administrator's session and gain unauthorized access to the server.
Remediation
Install updates from vendor's website.