CVE-2025-31161Active Exploitation(crushftp / crushftp)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for crushftp crushftp systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and April 2025, aka "Unauthenticated HTTP(S) port access." A race condition exists in the AWS4-HMAC (compatible with S3) authorization method of the HTTP component of the FTP server. The server first verifies the existence of the user by performing a call to login_user_pass() with no password requirement. This will authenticate the session through the HMAC verification process and up until the server checks for user verification once more. The vulnerability can be further stabilized, eliminating the need for successfully triggering a race condition, by sending a mangled AWS4-HMAC header. By providing only the username and a following slash (/), the server will successfully find a username, which triggers the successful anypass authentication process, but the server will fail to find the expected SignedHeaders entry, resulting in an index-out-of-bounds error that stops the code from reaching the session cleanup. Together, these issues make it trivial to authenticate as any known or guessable user (e.g., crushadmin), and can lead to a full compromise of the system by obtaining an administrative account.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-04-28. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-305

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crushftp

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC is present in monitored signal
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 6 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-02-15); latest day: 2
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
crushftp

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-02-15: 2Mentions · 2026-02-17: 1Mentions · 2026-03-03: 1Mentions · 2026-03-22: 1Mentions · 2026-05-14: 2PoC Mentioned / Linked · 2026-05-14: 1Active Exploitation · 2026-02-15: 2Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-05-14: 2Technical Details · 2026-03-03: 1Technical Details · 2026-05-14: 102-1502-1703-0303-2205-14
Signal classification3 categories
Active Exploitation
571.4%
Exploit
114.3%
General
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-152
Active Exploitation1Exploit1
2026-02-171
Active Exploitation1
2026-03-031
Active Exploitation1
2026-03-221
General1
2026-05-142
Active Exploitation2
Full discourse7 posts
  • Jamie Levy🦉@gleeda
    Active Exploitation

    Do you have mad skills 🥷and want to join the Adversary Tactics team at @HuntressLabs ? We're looking for that special someone to help lead our Rapid Response engagements. Some examples of deliverables are: * SolarWinds Web Help Desk: https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399 * React2Shell: https://www.huntress.com/blog/peerblight-linux-backdoor-exploits-react2shell * Gladinet / Triofox: https://www.huntress.com/blog/cve-2025-30406-critical-gladinet-centrestack-triofox-vulnerability-exploited-in-the-wild * CrushFTP: https://www.huntress.com/blog/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation

    Post summary

    The post highlights deliverables involving CVEs that are actively exploited, though it offers no technical or patch details.

    0231732317.7K
    9.8K followersView on X
  • Seb@seblatombe
    Active Exploitation

    ‼️ Tout comme Ankama Animations, la fuite de Les "Lascars 2" proviendrait d’un accès CrushFTP des studios Millimages, potentiellement lié à l’exploitation de la faille CVE-2025-31161. https://t.co/blftuCYv3r

    Post summary

    The tweet suggests that the 'Lascars 2' data breach was likely caused by active exploitation of CVE‑2025‑31161 via CrushFTP access, indicating real‑world attacks.

    0501634.2K
    94.8K followersView on X
  • PacketSmith@PacketSmith
    Active Exploitation

    Head over to Netomize's blog to learn about how we detect the exploitation of CrushFTP Vulnerability (CVE-2025-31161) with PacketSmith's Yara detection module, using the newly introduced track_state and flow_state keywords to the correlation engine. https://blog.netomize.ca/detecting-exploitation-of-crushftp-vulnerability-cve-2025-31161-with-packetsmith-yara-detection-module-using-track-state-and-flow-state

    Post summary

    The blog demonstrates detection of active exploitation of CVE‑2025‑31161 through a Yara module, indicating real‑world attacks but no PoC, exploit code, patch, or technical details are provided.

    020201.6K
    7 followersView on X
  • Anonymous Tech@Anonymous_Tech7
    Active Exploitation

    CrushFTP servers worldwide are under attack. Exploiting CVE-2024-4040 and CVE-2025-31161, attackers bypass authentication and achieve remote code execution, gaining control of the crushadmin account on vulnerable instances.

    Post summary

    Attackers are exploiting CVE-2024-4040 and CVE-2025-31161 to bypass authentication on CrushFTP servers, achieving remote code execution and taking control of the crushadmin account.

    00010125
    1 followersView on X
  • Exploit Technology@ExploitTech_US
    Exploit

    https://youtu.be/MCCM-KoyFwI HackTheBox - Soulmate walkthrough with Tehuti! -Subdomain discovery led to a vulnerable CrushFTP instance -Exploited CVE-2025-31161 to gain administrative access -Post-exploitation enumeration revealed a misconfigured Erlang service -Hardcoded credentials in a startup script → root access

    Post summary

    A HackTheBox walkthrough demonstrates exploitation of CVE-2025-31161 on CrushFTP, achieving admin and root access via a misconfigured Erlang service and hardcoded credentials.

    0001043
    24 followersView on X
  • ThreatAft@ThreatAft
    Active Exploitation

    🚨 CrushFTP CVE‑2025‑31161 (CVSS 9.8) – one HTTP request, full server takeover. Unauthenticated attackers can impersonate any user, including crushadmin. Exploited in the wild since March 2025. PoC available. 🔗 https://threataft.com/articles/crushftp-authentication-bypass-cve-2025-31161 #CyberSecurity #CrushFTP #MFT #CISAKEV

    Post summary

    CVE‑2025‑31161 is actively exploited in the wild, with a single HTTP request enabling full server takeover; a PoC exists, but no patches or mitigations are referenced.

    000001.6K
    24 followersView on X
  • ‘BBWriteups’@bbwriteup
    General

    "Crusher | CVE-2025–31161" by 0xDolphin #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@mousa92005/crusher-cve-2025-31161-6a21d36af548

    Post summary

    The text points to a Medium article about CVE-2025‑31161 but does not provide explicit details, PoC, exploit code, or other actionable information.

    00000109
    541 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcrushftpcrushftp---

Explore more