Missing authorization in CrushFTP - CVE-2025-31161,CVE-2025-2825
Published: March 26, 2025 / Updated: January 16, 2026
Vulnerability identifier: #VU106062
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31161,CVE-2025-2825
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a missing authorization. A remote attacker can directly connect to the web server interface without credentials and gain full control over the server.
Affected software
CrushFTP
How to mitigate CVE-2025-31161,CVE-2025-2825
Install updates from vendor's website.
CrushFTP - addressed in versions 10.8.4, 11.3.1
Links to Public Exploits and PoC-codes
- Exploit #12315 - CVE-2025-31161 (PoC Authentication Bypass to RCE to Exploit CVE-2025-31161) (January 16, 2026)
- Exploit #12104 - CVE-2025-31161 (November 14, 2025)
- Exploit #11944 - CVE-2025-31161 (September 12, 2025)
- Exploit #11844 - CVE-2025-2825-CrushFTP-AuthBypass (August 8, 2025)
- Exploit #11831 - CVE-2025-31161 (August 1, 2025)
- Exploit #11682 - CVE-2025-31161 (June 20, 2025)
- Exploit #11423 - CVE-2025-31161 (May 30, 2025)
- Exploit #11370 - CVE-2025-31161 (May 9, 2025)
- Exploit #11334 - CVE-2025-31161 (April 25, 2025)
- Exploit #11312 - ShatteredFTP (April 11, 2025)
- Exploit #11309 - CVE-2025-31161 (April 11, 2025)
- Exploit #11292 - CrushFTP AWS4-HMAC Authentication Bypass (April 4, 2025)
- Exploit #11289 - crushftp-CVE-2025-2825 (April 4, 2025)
- Exploit #11284 - CVE-2025-2825 (April 4, 2025)