Full Report
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-31161 to its Known Exploited Vulnerabilities (KEV) catalog
Analysis Summary
# Vulnerability: Critical Authentication Bypass in CrushFTP
## CVE Details
- CVE ID: CVE-2025-31161
- CVSS Score: 9.8 (Critical)
- CWE: Authentication Bypass (Implied by description)
## Affected Systems
- Products: CrushFTP
- Versions: CrushFTP v10 and v11 (Prior to the fixed versions listed below)
- Configurations: Unspecified, affects running instances of vulnerable versions.
## Vulnerability Description
The vulnerability is a critical authentication bypass flaw that allows an unauthenticated actor to gain unauthorized access and potentially take over devices running unpatched versions of CrushFTP v10 or v11.
## Exploitation
- Status: Exploited in the wild (Added to CISA KEV catalog)
- Complexity: Low (Implied by critical CVSS score and unauthenticated remote access)
- Attack Vector: Network (Implied by context of file transfer solution exploitation)
## Impact
- Confidentiality: High (Potential for unauthorized data access)
- Integrity: High (Potential for unauthorized data modification/system takeover)
- Availability: High (Potential for denial of service or system compromise)
## Remediation
### Patches
- CrushFTP version 10.8.4
- CrushFTP version 11.3.1
### Workarounds
No specific workarounds were detailed in the provided text, but immediate patching is strongly urged.
## Detection
- Indicators of compromise: Exploitation observed in the wild, requiring immediate threat hunting.
- Detection methods and tools: Organizations should consult CISA advisories for specific IoCs related to this KEV entry.
## References
- Vendor Advisories: CrushFTP disclosure on March 21 (Date mentioned)
- CISA KEV Link: cisa.gov/news-events/alerts/2025/04/07/cisa-adds-one-known-exploited-vulnerability-catalog (Defanged for safety)