CyberzSOC

Publication detail
← Back to advisories & guidance

2025-028: CrushFTP zero-day exploited in the wild ↗ source

July 24, 2025 CERT-EU Advisory

Summary

CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers [2, 3]. Threat actors were first detected exploiting the vulnerability on July 18th at 9AM CST, though it may have begun in the early hours of the previous day [1]. The attack occurs via the software’s web interface in versions prior to CrushFTP v10.8.5 and CrushFTP v11.3.4_23. It is unclear when these versions were released, but CrushFTP says Enterprise customers using a DMZ CrushFTP instance to isolate their main server are not believed to be affected by this vulnerability. We believe this bug was in builds prior to July 1st time period roughly. . . the latest versions of CrushFTP already have the issue patched. The attack vector was HTTP(S) for how they could exploit the server.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-54309 9.0 Critical CrushFTP CrushFTP CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.