CVE-2025-2825: CrushFTP HTTP Unauthenticated Access
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-31161. Reason: This Record is a reservation duplicate of CVE-2025-31161. Notes: All CVE users should reference CVE-2025-31161 instead of this Record. All references and descriptions in this Record have been removed to prevent accidental usage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2825?
CVE-2025-2825 is categorized as a critical vulnerability due to its potential for remote unauthenticated access.
How do I fix CVE-2025-2825?
To fix CVE-2025-2825, upgrade CrushFTP to versions 11.4.0 or later, or apply any available security patches.
Which versions of CrushFTP are affected by CVE-2025-2825?
CVE-2025-2825 affects CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0.
What type of attacks can occur due to CVE-2025-2825?
CVE-2025-2825 can allow attackers to perform unauthorized actions through unauthenticated HTTP requests.
Is authentication required to exploit CVE-2025-2825?
No, CVE-2025-2825 allows for exploitation without authentication, making it especially dangerous.