CVE-2025-54309
CrushFTP Authentication Bypass VulnerabilityCrushFTP 10 before 10.8.5 and 11 before 11.3.
2025-8-1 15:50:43
Author: horizon3.ai(查看原文)
阅读量:21
收藏
CrushFTP Authentication Bypass Vulnerability
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23 mishandles AS2 validation when the DMZ proxy feature is not used and consequently allows remote attackers to obtain admin access via HTTPS.
Unauthenticated remote attackers can bypass authentication on the affected CrushFTP device leading to unauthorized access.
Mitigations
Reference the vendor advisory for mitigation and update instructions.
Implement a continuous find, fix, and verify loop with NodeZero
The NodeZero® platform empowers your organization to reduce your security risks by autonomously finding exploitable weaknesses in your network, giving you detailed guidance around how to priortize and fix them, and having you immediately verify that your fixes are effective.