First published: Wed Mar 26 2025(Updated: )
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-31161. Reason: This Record is a reservation duplicate of CVE-2025-31161. Notes: All CVE users should reference CVE-2025-31161 instead of this Record. All references and descriptions in this Record have been removed to prevent accidental usage.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CrushFTP | >=10.0.0<=10.8.3>=11.0.0<=11.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2825 is categorized as a critical vulnerability due to its potential for remote unauthenticated access.
To fix CVE-2025-2825, upgrade CrushFTP to versions 11.4.0 or later, or apply any available security patches.
CVE-2025-2825 affects CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0.
CVE-2025-2825 can allow attackers to perform unauthorized actions through unauthenticated HTTP requests.
No, CVE-2025-2825 allows for exploitation without authentication, making it especially dangerous.