A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2025-54309

CrushFTP Unprotected Alternate Channel Vulnerability

Published
2025-07-22
Modified
2026-07-31
Sources
cisa-kev

Summary

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.