Over 1,000 CrushFTP instances currently exposed online are vulnerable to hijack attacks that exploit a critical security bug, providing admin access to the web interface. The security vulnerability (CVE-2025-54309) is due to mishandled AS2 validation and impacts all CrushFTP versions below 10.8.5 and 11.3.4_23. The vendor tagged the flaw as actively exploited in the wild on July 19th, noting that attacks may have begun earlier, although it has yet to find evidence to confirm this. "July 18th, 9AM CST there is a 0-day exploit seen in the wild. Possibly it has been going on for longer, but we saw it then. Hackers apparently reverse engineered our code and found some bug which we had already fixed," reads CrushFTP's advisory "They are exploiting it for anyone who has not stayed current on new versions. As always we recommend regularly and frequent patching. Anyone who had kept up to date was spared from this exploit." However, CrushFTP added last week that servers that have been kept up to date are not vulnerable to attacks, stating that customers who use a demilitarized zone (DMZ) instance to isolate their main server aren't impacted by this vulnerability. The company also recommends reviewing upload and download logs for unusual activity, as well as enabling automatic updates and whitelisting IPs for server and admin access to further mitigate exploitation attempts. According to scans from the security threat monitoring platform Shadowserver, approximately 1,040 CrushFTP inst...
Over 1,000 CrushFTP servers exposed to ongoing hijack attacks
BleepingComputer
·Sergiu Gatlan
·Published Jul 21, 2025
·Updated
Affected Software
2 affected components
CrushFTP CrushFTP=10.8.5
CrushFTP CrushFTP=11.3.4_23
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses ongoing hijack attacks affecting over 1,000 exposed CrushFTP servers due to a critical security vulnerability.
2
What security implications are discussed in this article?
The article highlights the risk of unauthorized admin access to CrushFTP web interfaces stemming from a critical vulnerability (CVE-2025-54309).
3
What products or software are affected by this security vulnerability?
The affected products include CrushFTP version 10.8.5 and version 11.3.4_23.
4
How many CrushFTP servers are currently exposed to hijack attacks?
Over 1,000 CrushFTP servers are currently exposed and vulnerable to hijack attacks.
5
What should users of CrushFTP do in light of this vulnerability?
Users of CrushFTP should take immediate steps to apply security updates and mitigate the risk of hijack attacks.