CVE-2025-32102: SSRF
Published Apr 15, 2025
·Updated
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI.
Affected Software
2 affected components
CrushFTP Crushftp>=9.0<10.8.4, >=11.0<11.3.1
CrushFTP Crushftp>=9.0.0<=11.3.1
Event History
Apr 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-32102?
CVE-2025-32102 is classified as a high severity vulnerability due to the potential for server-side request forgery (SSRF).
2
How do I fix CVE-2025-32102?
To mitigate CVE-2025-32102, upgrade CrushFTP to a version higher than 10.8.4 or 11.3.1.
3
What versions of CrushFTP are affected by CVE-2025-32102?
CVE-2025-32102 affects CrushFTP versions 9.x through 10.8.4 and 11.x through 11.3.1.
4
What type of attack is facilitated by CVE-2025-32102?
CVE-2025-32102 allows for server-side request forgery (SSRF) via the command=telnetSocket request.
5
What are the potential impacts of exploiting CVE-2025-32102?
Exploiting CVE-2025-32102 can lead to unauthorized access to internal services and sensitive information on the affected server.