Full Report
A critical authentication bypass flaw in CrushFTP is under active exploitation following a mishandled disclosure process
Analysis Summary
# Vulnerability: CrushFTP Critical Authentication Bypass Leading to Active Exploitation
## CVE Details
- CVE ID: CVE-2025-31161
- CVSS Score: 9.8 (Critical)
- CWE: Authentication Bypass (Inferred from context)
## Affected Systems
- Products: CrushFTP
- Versions: CrushFTP versions 10 and 11 (prior to identified patches)
- Configurations: Any unpatched device running affected versions.
## Vulnerability Description
A critical authentication bypass vulnerability exists in CrushFTP. This flaw allows unauthenticated remote attackers to gain access to devices running vulnerable versions of the software. The vulnerability was reportedly handled with a disrupted disclosure process, leading to premature public knowledge and immediate exploitation.
## Exploitation
- Status: Exploited in the wild
- Complexity: Not explicitly stated, but active exploitation suggests Low to Medium complexity.
- Attack Vector: Network (Remote access provided by the nature of the FTP service)
## Impact
- Confidentiality: High (Allows unauthorized access to systems hosting file transfer services)
- Integrity: High (Implied, as unauthorized access to an FTP server often allows file modification/upload)
- Availability: Medium to High (Potential for service disruption or data loss associated with compromise)
## Remediation
### Patches
- **CrushFTP v10:** Update to version **10.8.4** or higher.
- **CrushFTP v11:** Update to version **11.3.1** or higher.
### Workarounds
No specific workarounds are detailed in the provided text, but immediate patching is strongly urged. If patching is impossible, strict network segmentation and limiting external access to CrushFTP instances would be a standard emergency measure.
## Detection
- **Indicators of Compromise (IOCs):** Over 1500 vulnerable instances were identified online by Shadowserver Foundation, indicating high exposure risk.
- **Detection Methods and Tools:** Monitoring network traffic to CrushFTP ports for suspicious authentication attempts or successful unauthorized logins post-disclosure date (March 2025 timeline).
## References
- Vendor advisory sent to customers on March 21, 2025.
- Shadowserver Foundation report identifying vulnerable hosts (link defanged: `https://x.com/Shadowserver/status/1906753539499520064`)