1
0
1
0
1
0
1
0
0
1
1
0
1
0
VulnHub

AI-Powered Cybersecurity Intelligence

Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers

Source: The Hacker News | Added:

A critical security flaw in CrushFTP, identified as CVE-2025-54309, has been disclosed and is currently being exploited in the wild. The vulnerability allows remote attackers to gain admin access on unpatched servers through mishandled AS2 validation when the DMZ proxy feature is not used.


Impact: CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23

In the Wild: Yes

Age: Newly disclosed

Remediation: Not specified

CVE Exploit Vulnerability
Read Full Original Article →