Description CrushFTP 10.0.0至10.8.3版本以及11.0.0至11.3.0版本存在身份验证绕过漏洞,攻击者可通过构造特殊的HTTP请求绕过身份验证,最终可能导致系统完全沦陷。
References https://blog.csdn.net/m0_50125527/article/details/146972819 https://tencentcloud.csdn.net/69ea42480a2f6a37c5a3ae97.html https://cn-sec.com/archives/3921226.html https://idocdown.com/app/articles/blogs/detail/16311 https://github.com/Threekiii/CVE/blob/master/README.md https://cn-sec.com/archives/3927094.html https://projectdiscovery.io/blog/crushftp-authentication-bypass https://nvd.nist.gov/vuln/detail/CVE-2025-2825 https://www.ionix.io/blog/critical-unauthenticated-access-vulnerability-in-crushftp-cve-2025-2825/ https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Compromise https://www.sonicwall.com/blog/critical-crushftp-authentication-bypass-cve-2025-2825-exposes-servers-to-remote-attacks https://attackerkb.com/topics/k0EgiL9Psz/cve-2025-2825 https://www.helpnetsecurity.com/2025/03/27/crushftp-vulnerability-cve-2025-2825/ https://github.com/punitdarji/crushftp-CVE-2025-2825 https://cn-sec.com/archives/3938861.html
Related VulnerabilitiesPoCCVE-2025-54309: CrushFTP - Authentication Bypass Race ConditionPoCCVE-2023-43177: CrushFTP < 10.5.1 - Unauthenticated Remote Code ExecutionPoCCVE-2024-4040: CrushFTP VFS - Sandbox Escape LFRPoCCVE-2025-31161: CrushFTP - Authentication BypassPoCcrushftp-anonymous-login: CrushFTP - Anonymous LoginPoCcrushftp-default-login: CrushFTP - Default Login(CVE-2025-54309)CrushFTP AS2验证漏洞导致远程管理员权限提升CrushFTP /WebInterface/function/ 权限绕过漏洞(CVE-2025-31161)CrushFTP 存在身份验证绕过漏洞(CVE-2025-2825)CrushFTP 身份鉴权绕过漏洞CrushFTP CVE-2024-4040 服务端模板注入漏洞CrushFTP /WebInterface/function 文件读取漏洞