First published: Wed Mar 26 2025(Updated: )
CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability that may result in unauthenticated access. Remote and unauthenticated HTTP requests to CrushFTP may allow attackers to gain unauthorized access.
Credit: disclosure@vulncheck.com
Affected Software | Affected Version | How to fix |
---|---|---|
CrushFTP | >=10.0.0<=10.8.3>=11.0.0<=11.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2825 is categorized as a critical vulnerability due to its potential for remote unauthenticated access.
To fix CVE-2025-2825, upgrade CrushFTP to versions 11.4.0 or later, or apply any available security patches.
CVE-2025-2825 affects CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0.
CVE-2025-2825 can allow attackers to perform unauthorized actions through unauthenticated HTTP requests.
No, CVE-2025-2825 allows for exploitation without authentication, making it especially dangerous.