A AegiFlow
UNKNOWNKNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2025-31161

CrushFTP Authentication Bypass Vulnerability

Published
2025-04-07
Modified
2026-07-31
Sources
cisa-kev

Summary

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.