https://reddit.com/r/cybersecurity/comments/1td2ecj/detecting_exploitation_of_crushftp_vulnerability/: Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
Published May 14, 2026
·Updated
Affected Software
1 affected component
CrushFTP CrushFTP
Frequently Asked Questions
1
What is the severity of CVE-2025-31161?
CVE-2025-31161 is classified as a medium-severity vulnerability.
2
How do I fix CVE-2025-31161?
To fix CVE-2025-31161, ensure that you update CrushFTP to the latest patched version provided by the vendor.
3
What systems are affected by CVE-2025-31161?
CVE-2025-31161 affects all versions of CrushFTP prior to the security update.
4
How can I detect exploitation attempts of CVE-2025-31161?
Exploitation attempts of CVE-2025-31161 can be detected using PacketSmith’s Yara detection module with the specific keywords track_state and flow_state.
5
Is there any workaround for CVE-2025-31161 until a patch is applied?
A temporary workaround for CVE-2025-31161 includes restricting access to the CrushFTP service from untrusted networks.