• News/
  • https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-unauthenticated-access-flaw-immediately/

CrushFTP warns users to patch unauthenticated access flaw immediately

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 25, 2025
·
Updated

CrushFTP warned customers of an authentication bypass security vulnerability and urged them to patch their servers immediately. As the company also explained in an email sent to customers on Friday (seen by BleepingComputer), this critical-severity authentication bypass flaw (now tracked as CVE-2025-2825) enables attackers to gain access to unpatched servers if they are exposed on the Internet over HTTP(S). "Please take immediate action to patch ASAP. A vulnerability has been addressed today (March 21st, 2025). All CrushFTP v11 versions were affected. (No earlier versions are affected.)," the company warned. "The bottom line of this vulnerability is that an exposed HTTP(S) port could lead to unauthenticated access. The vulnerability is mitigated If you have the DMZ feature of CrushFTP in place." While the email says this vulnerability only affects CrushFTP v11 versions, an advisory issued on the same day says that both CrushFTP v10 and v11 are impacted, as cybersecurity company Rapid7 first noted. As a workaround, those who can't immediately update CrushFTP to versions 10.8.4+ or 11.3.1+ can enable the DMZ (demilitarized zone) perimeter network option to protect their CrushFTP instance until security updates can be deployed. According to Shodan, over 3,400 CrushFTP instances have their web interface exposed online to attacks, although BleepingComputer couldn't determine how many have already been patched. However, searching for all CrushFTP servers reachable over the Interne...

Read full article

Affected Software

4 affected components
CrushFTP CrushFTP=10
CrushFTP CrushFTP=11
CrushFTP CrushFTP=v10
CrushFTP CrushFTP=v11

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical authentication bypass vulnerability in CrushFTP software that requires immediate patching.

2

What security implications are discussed in the article?

The article highlights the risk of unauthenticated access to servers running affected versions of CrushFTP, which could allow unauthorized users to exploit the vulnerability.

3

What products or software are affected by the vulnerability?

The vulnerability affects CrushFTP versions 10 and 11.

4

What action does CrushFTP recommend to its users?

CrushFTP urges its users to urgently apply patches to their servers to mitigate the security risk.

5

When was the warning about the vulnerability issued to customers?

The warning was issued in an email sent to customers on a Friday, as reported by BleepingComputer.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203