• News/
  • https://www.bleepingcomputer.com/news/security/new-crushftp-zero-day-exploited-in-attacks-to-hijack-servers/

New CrushFTP zero-day exploited in attacks to hijack servers

BleepingComputer
·
Lawrence Abrams
·
Published Jul 18, 2025
·
Updated

CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers. CrushFTP is an enterprise file transfer server used by organizations to securely share and manage files over FTP, SFTP, HTTP/S, and other protocols. According to CrushFTP, threat actors were first detected exploiting the vulnerability on July 18th at 9AM CST, though it may have begun in the early hours of the previous day. CrushFTP CEO Ben Spink told BleepingComputer that they had previously fixed a vulnerability related to AS2 in HTTP(S) that inadvertantly blocked this zero-day flaw as well. "A prior fix by chance happened to block this vulnerability too, but the prior fix was targeting a different issue and turning off some rarely used feature by default," Spink told BleepingComputer. CrushFTP says it believes threat actors reverse engineered their software and discovered this new bug and had begun exploiting it on devices that are not up-to-date on their patches. "We believe this bug was in builds prior to July 1st time period roughly...the latest versions of CrushFTP already have the issue patched," reads CrushFTP's advisory. "The attack vector was HTTP(S) for how they could exploit the server. We had fixed a different issue related to AS2 in HTTP(S) not realizing that prior bug could be used like this exploit was. Hackers apparently saw our code change, and fig...

Read full article

Affected Software

2 affected components
CrushFTP CrushFTP<10.8.5
CrushFTP CrushFTP<11.3.4_23

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in CrushFTP that is being actively exploited by attackers.

2

What security implications are discussed in the article?

The article highlights that the vulnerability allows attackers to gain administrative access to vulnerable servers, posing significant security risks.

3

What vulnerability is identified in the article?

The vulnerability is tracked as CVE-2025-54309.

4

Which versions of CrushFTP are affected by this vulnerability?

The affected versions of CrushFTP are from 10.8.5 up to 11.3.4_23.

5

Who is responsible for addressing the zero-day vulnerability?

CrushFTP is responsible for addressing the zero-day vulnerability and providing a fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203