• News/
  • https://www.theregister.com/2025/03/27/crushftp_cve/

CrushFTP CEO's feisty response to VulnCheck's CVE for critical make-me-admin bug

The Register
·
Connor Jones
·
Published Mar 27, 2025
·
Updated

CrushFTP's CEO is not happy with VulnCheck after the CVE numbering authority (CNA) released an unofficial ID for the critical vulnerability in its file transfer tech disclosed almost a week ago. According to an email exchange between CrushFTP's Ben Spink and VulnCheck's CTO Jacob Baines, shared by the latter as a screenshot on X on Wednesday, Spink responded to the CNA aggressively after Baines sent an email about the issuance of CVE-2025-2825 (9.8). Spink's response email purportedly read: "You don't know any details on this issue. Yours [CVE] will be deleted as a duplicate. You did not discover this. The real CVE is pending. Your reputation will go down if you do not voluntarily remove your fake item. It will be blatantly obvious when the real CVE is live since it literally explains in detail the vulnerability you know nothing about. "Please note! Due to a recent vulnerability, make certain you are using either CrushFTP v10.8.4+ or v11.3.1. Anything earlier is unsafe!" For context, CrushFTP told customers via email on March 21 about a critical vulnerability, prompting them to "take immediate action to patch ASAP." It also promised to generate a CVE "soon." It is now six days later and a CVE from CrushFTP itself has not yet materialized. Assigning CVEs for vulnerabilities in a timely manner is important for defenders so they can easily track and prioritize the issues affecting their IT estate. Withholding them can lead to confusion and delays for customers. CrushFTP's own ad...

Read full article

Affected Software

5 affected components
CrushFTP CrushFTP=10.8.4
CrushFTP CrushFTP=11.3.1
CrushFTP CrushFTP
CrushFTP CrushFTP=10.8.4
CrushFTP CrushFTP=11.3.1

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in CrushFTP's file transfer technology and the response of its CEO to the unofficial CVE issued by VulnCheck.

2

What security implications are discussed in the article?

The article highlights a critical 'make-me-admin' bug that poses significant security risks for users of CrushFTP.

3

What products are affected by this vulnerability?

The vulnerability affects CrushFTP versions 10.8.4 and 11.3.1.

4

Who issued the unofficial CVE for this vulnerability?

The unofficial CVE for the vulnerability was issued by VulnCheck.

5

How did CrushFTP's CEO respond to the CVE release?

CrushFTP's CEO expressed displeasure with VulnCheck regarding the release of the unofficial CVE.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203