https://reddit.com/r/cybersecurity/comments/1k5als5/cve202531161_is_being_actively_exploited_and_its/: CVE-2025-31161 is being actively exploited and it's not getting the attention it should.
Published Apr 22, 2025
·Updated
Affected Software
1 affected component
CrushFTP Crushftp>=10.0.0<=10.8.3, >=11.0.0<=11.3.0
Frequently Asked Questions
1
What is the severity of CVE-2025-31161?
CVE-2025-31161 is classified as a critical vulnerability due to its potential to allow unauthorized access to sensitive files.
2
How do I fix CVE-2025-31161?
To resolve CVE-2025-31161, upgrade your CrushFTP version to 11.3.1 or later, where the vulnerability has been patched.
3
Which versions of CrushFTP are affected by CVE-2025-31161?
CVE-2025-31161 affects CrushFTP versions 10.0.0 to 10.8.3 and 11.0.0 to 11.3.0.
4
What types of attacks can exploit CVE-2025-31161?
CVE-2025-31161 can be exploited to perform authentication bypass, allowing attackers unauthorized access to files and full system control.
5
Is there a known mitigation for CVE-2025-31161?
The recommended mitigation for CVE-2025-31161 is to immediately update to the latest version of CrushFTP that addresses this vulnerability.