CVE-2025-54309: CrushFTP Unprotected Alternate Channel Vulnerability
CrushFTP 10 before 10.8.5 and 11 before 11.3.423, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
Other sources
CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CrushFTPto a version that resolves this vulnerability.Fixed in 10.8.5 - Upgrade
Upgrade
CrushFTPto a version that resolves this vulnerability.Fixed in 11.3.4_23 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54309?
CVE-2025-54309 is considered a critical vulnerability due to its potential to allow remote attackers administrative access.
How do I fix CVE-2025-54309?
To fix CVE-2025-54309, upgrade to CrushFTP versions 10.8.5 or 11.3.4_23 or later.
What systems are affected by CVE-2025-54309?
CVE-2025-54309 affects CrushFTP versions prior to 10.8.5 and 11 prior to 11.3.4_23.
Can CVE-2025-54309 be exploited without using the DMZ proxy feature?
Yes, CVE-2025-54309 can be exploited without the use of the DMZ proxy feature.
Is there evidence of active exploitation for CVE-2025-54309?
Yes, CVE-2025-54309 was exploited in the wild as of July 2025.