References https://nvd.nist.gov/vuln/detail/CVE-2025-54309 https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 https://www.rapid7.com/blog/post/crushftp-zero-day-exploited-in-the-wild/ https://zeropath.com/blog/crushftp-cve-2025-54309-as2-validation-flaw https://reliaquest.com/blog/threat-spotlight-cve-2025-54309-crushftp-exploit/ https://guardz.com/blog/critical-zero-day-in-crushftp-actively-exploited/ https://www.bleepingcomputer.com/news/security/crushftp-zero-day-exploited-in-attacks-to-gain-admin-access-on-servers/ https://www.cve.org/CVERecord?id=CVE-2025-54309 https://arcticwolf.com/resources/blog/cve-2025-54309-critical-zero-day-vulnerability-in-crushftp-exploited/ https://fidelissecurity.com/vulnerabilities/cve-2025-54309/
Related VulnerabilitiesPoCCVE-2025-54309: CrushFTP - Authentication Bypass Race ConditionPoCCVE-2023-43177: CrushFTP < 10.5.1 - Unauthenticated Remote Code ExecutionPoCCVE-2024-4040: CrushFTP VFS - Sandbox Escape LFRPoCCVE-2025-31161: CrushFTP - Authentication BypassPoCcrushftp-anonymous-login: CrushFTP - Anonymous LoginPoCcrushftp-default-login: CrushFTP - Default LoginCrushFTP /WebInterface/function/ 未授权访问漏洞 (CVE-2025-2825)CrushFTP /WebInterface/function/ 权限绕过漏洞(CVE-2025-31161)CrushFTP 存在身份验证绕过漏洞(CVE-2025-2825)CrushFTP 身份鉴权绕过漏洞CrushFTP CVE-2024-4040 服务端模板注入漏洞