Hackers Exploit Critical CrushFTP Zero-Day to Compromise Servers

TL;DR
A critical flaw in CrushFTP (CVE-2025-54309) is actively exploited, allowing remote attackers to gain admin access on unpatched servers, especially affecting sensitive environments. The vulnerability, present in versions before 10.8.5 and 11.3.4_23, involves mishandling AS2 validation and can be exploited via HTTP(S). Organizations are advised to review logs, restrict IPs, and update to mitigate risks, as multiple CVEs have targeted CrushFTP recently.
Topics:technologysecurity#admin-access#crushftp#cve-2025-54309#exploitation#security#security-vulnerability
- Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers The Hacker News
- Over 1,000 CrushFTP servers exposed to ongoing hijack attacks BleepingComputer
- Critical Zero-Day Exposes FTP Servers To Attack Forbes
- CrushFTP with 0-day vulnerability CVE-2025-54309 | Born's Tech and Windows World BornCity
- Hackers Target Zero-Day Vulnerability to Exploit CrushFTP BankInfoSecurity
Want the full story? Read the original reporting
Read on The Hacker News