Vulnerability Details CVE-2025-54309
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.621
EPSS Ranking 98.3%
CVSS Severity
CVSS v3 Score 9.0
Proposed Action
CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.
Ransomware Campaign
Unknown
Products affected by CVE-2025-54309
-
cpe:2.3:a:crushftp:crushftp:10.0.0
-
cpe:2.3:a:crushftp:crushftp:10.1.0
-
cpe:2.3:a:crushftp:crushftp:10.2.0
-
cpe:2.3:a:crushftp:crushftp:10.3.0
-
cpe:2.3:a:crushftp:crushftp:10.4.0
-
cpe:2.3:a:crushftp:crushftp:10.5.0
-
cpe:2.3:a:crushftp:crushftp:10.5.1
-
cpe:2.3:a:crushftp:crushftp:10.5.2
-
cpe:2.3:a:crushftp:crushftp:10.5.3
-
cpe:2.3:a:crushftp:crushftp:10.5.4
-
cpe:2.3:a:crushftp:crushftp:10.5.5
-
cpe:2.3:a:crushftp:crushftp:10.5.6
-
cpe:2.3:a:crushftp:crushftp:10.6.0
-
cpe:2.3:a:crushftp:crushftp:10.6.1
-
cpe:2.3:a:crushftp:crushftp:10.7.0
-
cpe:2.3:a:crushftp:crushftp:10.7.1
-
cpe:2.3:a:crushftp:crushftp:10.8.0
-
cpe:2.3:a:crushftp:crushftp:10.8.1
-
cpe:2.3:a:crushftp:crushftp:10.8.2
-
cpe:2.3:a:crushftp:crushftp:10.8.3
-
cpe:2.3:a:crushftp:crushftp:10.8.4
-
cpe:2.3:a:crushftp:crushftp:11.0.0
-
cpe:2.3:a:crushftp:crushftp:11.0.1
-
cpe:2.3:a:crushftp:crushftp:11.0.1_1
-
cpe:2.3:a:crushftp:crushftp:11.0.1_10
-
cpe:2.3:a:crushftp:crushftp:11.0.1_11
-
cpe:2.3:a:crushftp:crushftp:11.0.1_12
-
cpe:2.3:a:crushftp:crushftp:11.0.1_13
-
cpe:2.3:a:crushftp:crushftp:11.0.1_14
-
cpe:2.3:a:crushftp:crushftp:11.0.1_15
-
cpe:2.3:a:crushftp:crushftp:11.0.1_16
-
cpe:2.3:a:crushftp:crushftp:11.0.1_17
-
cpe:2.3:a:crushftp:crushftp:11.0.1_18
-
cpe:2.3:a:crushftp:crushftp:11.0.1_19
-
cpe:2.3:a:crushftp:crushftp:11.0.1_2
-
cpe:2.3:a:crushftp:crushftp:11.0.1_20
-
cpe:2.3:a:crushftp:crushftp:11.0.1_21
-
cpe:2.3:a:crushftp:crushftp:11.0.1_22
-
cpe:2.3:a:crushftp:crushftp:11.0.1_23
-
cpe:2.3:a:crushftp:crushftp:11.0.1_24
-
cpe:2.3:a:crushftp:crushftp:11.0.1_25
-
cpe:2.3:a:crushftp:crushftp:11.0.1_26
-
cpe:2.3:a:crushftp:crushftp:11.0.1_27
-
cpe:2.3:a:crushftp:crushftp:11.0.1_28
-
cpe:2.3:a:crushftp:crushftp:11.0.1_29
-
cpe:2.3:a:crushftp:crushftp:11.0.1_3
-
cpe:2.3:a:crushftp:crushftp:11.0.1_30
-
cpe:2.3:a:crushftp:crushftp:11.0.1_4
-
cpe:2.3:a:crushftp:crushftp:11.0.1_5
-
cpe:2.3:a:crushftp:crushftp:11.0.1_6
-
cpe:2.3:a:crushftp:crushftp:11.0.1_7
-
cpe:2.3:a:crushftp:crushftp:11.0.1_8
-
cpe:2.3:a:crushftp:crushftp:11.0.1_9
-
cpe:2.3:a:crushftp:crushftp:11.1.0
-
cpe:2.3:a:crushftp:crushftp:11.1.0_0
-
cpe:2.3:a:crushftp:crushftp:11.1.0_1
-
cpe:2.3:a:crushftp:crushftp:11.1.0_10
-
cpe:2.3:a:crushftp:crushftp:11.1.0_11
-
cpe:2.3:a:crushftp:crushftp:11.1.0_12
-
cpe:2.3:a:crushftp:crushftp:11.1.0_13
-
cpe:2.3:a:crushftp:crushftp:11.1.0_14
-
cpe:2.3:a:crushftp:crushftp:11.1.0_15
-
cpe:2.3:a:crushftp:crushftp:11.1.0_16
-
cpe:2.3:a:crushftp:crushftp:11.1.0_17
-
cpe:2.3:a:crushftp:crushftp:11.1.0_18
-
cpe:2.3:a:crushftp:crushftp:11.1.0_19
-
cpe:2.3:a:crushftp:crushftp:11.1.0_2
-
cpe:2.3:a:crushftp:crushftp:11.1.0_20
-
cpe:2.3:a:crushftp:crushftp:11.1.0_21
-
cpe:2.3:a:crushftp:crushftp:11.1.0_3
-
cpe:2.3:a:crushftp:crushftp:11.1.0_4
-
cpe:2.3:a:crushftp:crushftp:11.1.0_5
-
cpe:2.3:a:crushftp:crushftp:11.1.0_6
-
cpe:2.3:a:crushftp:crushftp:11.1.0_7
-
cpe:2.3:a:crushftp:crushftp:11.1.0_8
-
cpe:2.3:a:crushftp:crushftp:11.1.0_9
-
cpe:2.3:a:crushftp:crushftp:11.2.0
-
cpe:2.3:a:crushftp:crushftp:11.2.0_0
-
cpe:2.3:a:crushftp:crushftp:11.2.0_1
-
cpe:2.3:a:crushftp:crushftp:11.2.0_2
-
cpe:2.3:a:crushftp:crushftp:11.2.0_3
-
cpe:2.3:a:crushftp:crushftp:11.2.0_4
-
cpe:2.3:a:crushftp:crushftp:11.2.0_5
-
cpe:2.3:a:crushftp:crushftp:11.2.0_6
-
cpe:2.3:a:crushftp:crushftp:11.2.0_7
-
cpe:2.3:a:crushftp:crushftp:11.2.0_8
-
cpe:2.3:a:crushftp:crushftp:11.2.0_9
-
cpe:2.3:a:crushftp:crushftp:11.2.1
-
cpe:2.3:a:crushftp:crushftp:11.2.1_10
-
cpe:2.3:a:crushftp:crushftp:11.2.1_11
-
cpe:2.3:a:crushftp:crushftp:11.2.1_12
-
cpe:2.3:a:crushftp:crushftp:11.2.1_13
-
cpe:2.3:a:crushftp:crushftp:11.2.1_14
-
cpe:2.3:a:crushftp:crushftp:11.2.1_15
-
cpe:2.3:a:crushftp:crushftp:11.2.1_16
-
cpe:2.3:a:crushftp:crushftp:11.2.1_17
-
cpe:2.3:a:crushftp:crushftp:11.2.1_18
-
cpe:2.3:a:crushftp:crushftp:11.2.1_19
-
cpe:2.3:a:crushftp:crushftp:11.2.1_20
-
cpe:2.3:a:crushftp:crushftp:11.2.1_21
-
cpe:2.3:a:crushftp:crushftp:11.2.1_22
-
cpe:2.3:a:crushftp:crushftp:11.2.1_23
-
cpe:2.3:a:crushftp:crushftp:11.2.2
-
cpe:2.3:a:crushftp:crushftp:11.2.2_0
-
cpe:2.3:a:crushftp:crushftp:11.2.2_1
-
cpe:2.3:a:crushftp:crushftp:11.2.2_10
-
cpe:2.3:a:crushftp:crushftp:11.2.2_11
-
cpe:2.3:a:crushftp:crushftp:11.2.2_13
-
cpe:2.3:a:crushftp:crushftp:11.2.2_2
-
cpe:2.3:a:crushftp:crushftp:11.2.2_3
-
cpe:2.3:a:crushftp:crushftp:11.2.2_4
-
cpe:2.3:a:crushftp:crushftp:11.2.2_5
-
cpe:2.3:a:crushftp:crushftp:11.2.2_6
-
cpe:2.3:a:crushftp:crushftp:11.2.2_7
-
cpe:2.3:a:crushftp:crushftp:11.2.2_8
-
cpe:2.3:a:crushftp:crushftp:11.2.2_9
-
cpe:2.3:a:crushftp:crushftp:11.2.3
-
cpe:2.3:a:crushftp:crushftp:11.2.3_0
-
cpe:2.3:a:crushftp:crushftp:11.2.3_1
-
cpe:2.3:a:crushftp:crushftp:11.2.3_10
-
cpe:2.3:a:crushftp:crushftp:11.2.3_11
-
cpe:2.3:a:crushftp:crushftp:11.2.3_12
-
cpe:2.3:a:crushftp:crushftp:11.2.3_13
-
cpe:2.3:a:crushftp:crushftp:11.2.3_14
-
cpe:2.3:a:crushftp:crushftp:11.2.3_15
-
cpe:2.3:a:crushftp:crushftp:11.2.3_16
-
cpe:2.3:a:crushftp:crushftp:11.2.3_17
-
cpe:2.3:a:crushftp:crushftp:11.2.3_18
-
cpe:2.3:a:crushftp:crushftp:11.2.3_19
-
cpe:2.3:a:crushftp:crushftp:11.2.3_2
-
cpe:2.3:a:crushftp:crushftp:11.2.3_20
-
cpe:2.3:a:crushftp:crushftp:11.2.3_21
-
cpe:2.3:a:crushftp:crushftp:11.2.3_22
-
cpe:2.3:a:crushftp:crushftp:11.2.3_23
-
cpe:2.3:a:crushftp:crushftp:11.2.3_24
-
cpe:2.3:a:crushftp:crushftp:11.2.3_25
-
cpe:2.3:a:crushftp:crushftp:11.2.3_26
-
cpe:2.3:a:crushftp:crushftp:11.2.3_27
-
cpe:2.3:a:crushftp:crushftp:11.2.3_3
-
cpe:2.3:a:crushftp:crushftp:11.2.3_4
-
cpe:2.3:a:crushftp:crushftp:11.2.3_5
-
cpe:2.3:a:crushftp:crushftp:11.2.3_6
-
cpe:2.3:a:crushftp:crushftp:11.2.3_7
-
cpe:2.3:a:crushftp:crushftp:11.2.3_8
-
cpe:2.3:a:crushftp:crushftp:11.2.3_9
-
cpe:2.3:a:crushftp:crushftp:11.3.0
-
cpe:2.3:a:crushftp:crushftp:11.3.0_0
-
cpe:2.3:a:crushftp:crushftp:11.3.0_1
-
cpe:2.3:a:crushftp:crushftp:11.3.0_2
-
cpe:2.3:a:crushftp:crushftp:11.3.0_3
-
cpe:2.3:a:crushftp:crushftp:11.3.0_4
-
cpe:2.3:a:crushftp:crushftp:11.3.0_5
-
cpe:2.3:a:crushftp:crushftp:11.3.1
-
cpe:2.3:a:crushftp:crushftp:11.3.1_10
-
cpe:2.3:a:crushftp:crushftp:11.3.1_11
-
cpe:2.3:a:crushftp:crushftp:11.3.1_12
-
cpe:2.3:a:crushftp:crushftp:11.3.1_13
-
cpe:2.3:a:crushftp:crushftp:11.3.1_14
-
cpe:2.3:a:crushftp:crushftp:11.3.1_15
-
cpe:2.3:a:crushftp:crushftp:11.3.1_16
-
cpe:2.3:a:crushftp:crushftp:11.3.1_17
-
cpe:2.3:a:crushftp:crushftp:11.3.1_18
-
cpe:2.3:a:crushftp:crushftp:11.3.1_19
-
cpe:2.3:a:crushftp:crushftp:11.3.1_20
-
cpe:2.3:a:crushftp:crushftp:11.3.1_21
-
cpe:2.3:a:crushftp:crushftp:11.3.1_22
-
cpe:2.3:a:crushftp:crushftp:11.3.1_23
-
cpe:2.3:a:crushftp:crushftp:11.3.1_24
-
cpe:2.3:a:crushftp:crushftp:11.3.1_25
-
cpe:2.3:a:crushftp:crushftp:11.3.1_26
-
cpe:2.3:a:crushftp:crushftp:11.3.1_27
-
cpe:2.3:a:crushftp:crushftp:11.3.1_28
-
cpe:2.3:a:crushftp:crushftp:11.3.1_29
-
cpe:2.3:a:crushftp:crushftp:11.3.1_30
-
cpe:2.3:a:crushftp:crushftp:11.3.1_31
-
cpe:2.3:a:crushftp:crushftp:11.3.1_32
-
cpe:2.3:a:crushftp:crushftp:11.3.1_6
-
cpe:2.3:a:crushftp:crushftp:11.3.1_7
-
cpe:2.3:a:crushftp:crushftp:11.3.1_8
-
cpe:2.3:a:crushftp:crushftp:11.3.1_9
-
cpe:2.3:a:crushftp:crushftp:11.3.2
-
cpe:2.3:a:crushftp:crushftp:11.3.2_0
-
cpe:2.3:a:crushftp:crushftp:11.3.2_1
-
cpe:2.3:a:crushftp:crushftp:11.3.2_2
-
cpe:2.3:a:crushftp:crushftp:11.3.2_3
-
cpe:2.3:a:crushftp:crushftp:11.3.2_4
-
cpe:2.3:a:crushftp:crushftp:11.3.2_5
-
cpe:2.3:a:crushftp:crushftp:11.3.3
-
cpe:2.3:a:crushftp:crushftp:11.3.3_10
-
cpe:2.3:a:crushftp:crushftp:11.3.3_11
-
cpe:2.3:a:crushftp:crushftp:11.3.3_12
-
cpe:2.3:a:crushftp:crushftp:11.3.3_13
-
cpe:2.3:a:crushftp:crushftp:11.3.3_14
-
cpe:2.3:a:crushftp:crushftp:11.3.3_15
-
cpe:2.3:a:crushftp:crushftp:11.3.3_16
-
cpe:2.3:a:crushftp:crushftp:11.3.3_17
-
cpe:2.3:a:crushftp:crushftp:11.3.3_18
-
cpe:2.3:a:crushftp:crushftp:11.3.3_19
-
cpe:2.3:a:crushftp:crushftp:11.3.3_6
-
cpe:2.3:a:crushftp:crushftp:11.3.3_7
-
cpe:2.3:a:crushftp:crushftp:11.3.3_8
-
cpe:2.3:a:crushftp:crushftp:11.3.3_9
-
cpe:2.3:a:crushftp:crushftp:11.3.4
-
cpe:2.3:a:crushftp:crushftp:11.3.4_20
-
cpe:2.3:a:crushftp:crushftp:11.3.4_21
-
cpe:2.3:a:crushftp:crushftp:11.3.4_22