
CrushFTP servers worldwide are under attack. Exploiting CVE-2024-4040 and CVE-2025-31161, attackers bypass authentication and achieve remote code execution, gaining control of the crushadmin account on vulnerable instances.
Post summary
Attackers are actively exploiting CVE‑2024‑4040 and CVE‑2025‑31161 on CrushFTP servers worldwide to bypass authentication, achieve remote code execution, and seize control of the crushadmin account.
