• News/
  • https://www.bleepingcomputer.com/news/security/over-1-000-crushftp-servers-exposed-to-ongoing-hijack-attacks/

Over 1,000 CrushFTP servers exposed to ongoing hijack attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jul 21, 2025
·
Updated

Over 1,000 CrushFTP instances currently exposed online are vulnerable to hijack attacks that exploit a critical security bug, providing admin access to the web interface. The security vulnerability (CVE-2025-54309) is due to mishandled AS2 validation and impacts all CrushFTP versions below 10.8.5 and 11.3.4_23. The vendor tagged the flaw as actively exploited in the wild on July 19th, noting that attacks may have begun earlier, although it has yet to find evidence to confirm this. "July 18th, 9AM CST there is a 0-day exploit seen in the wild. Possibly it has been going on for longer, but we saw it then. Hackers apparently reverse engineered our code and found some bug which we had already fixed," reads CrushFTP's advisory "They are exploiting it for anyone who has not stayed current on new versions. As always we recommend regularly and frequent patching. Anyone who had kept up to date was spared from this exploit." However, CrushFTP added last week that servers that have been kept up to date are not vulnerable to attacks, stating that customers who use a demilitarized zone (DMZ) instance to isolate their main server aren't impacted by this vulnerability. The company also recommends reviewing upload and download logs for unusual activity, as well as enabling automatic updates and whitelisting IPs for server and admin access to further mitigate exploitation attempts. According to scans from the security threat monitoring platform Shadowserver, approximately 1,040 CrushFTP inst...

Read full article

Affected Software

2 affected components
CrushFTP CrushFTP=10.8.5
CrushFTP CrushFTP=11.3.4_23

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses ongoing hijack attacks affecting over 1,000 exposed CrushFTP servers due to a critical security vulnerability.

2

What security implications are discussed in this article?

The article highlights the risk of unauthorized admin access to CrushFTP web interfaces stemming from a critical vulnerability (CVE-2025-54309).

3

What products or software are affected by this security vulnerability?

The affected products include CrushFTP version 10.8.5 and version 11.3.4_23.

4

How many CrushFTP servers are currently exposed to hijack attacks?

Over 1,000 CrushFTP servers are currently exposed and vulnerable to hijack attacks.

5

What should users of CrushFTP do in light of this vulnerability?

Users of CrushFTP should take immediate steps to apply security updates and mitigate the risk of hijack attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203