CrushFTP's CEO is not happy with VulnCheck after the CVE numbering authority (CNA) released an unofficial ID for the critical vulnerability in its file transfer tech disclosed almost a week ago. According to an email exchange between CrushFTP's Ben Spink and VulnCheck's CTO Jacob Baines, shared by the latter as a screenshot on X on Wednesday, Spink responded to the CNA aggressively after Baines sent an email about the issuance of CVE-2025-2825 (9.8). Spink's response email purportedly read: "You don't know any details on this issue. Yours [CVE] will be deleted as a duplicate. You did not discover this. The real CVE is pending. Your reputation will go down if you do not voluntarily remove your fake item. It will be blatantly obvious when the real CVE is live since it literally explains in detail the vulnerability you know nothing about. "Please note! Due to a recent vulnerability, make certain you are using either CrushFTP v10.8.4+ or v11.3.1. Anything earlier is unsafe!" For context, CrushFTP told customers via email on March 21 about a critical vulnerability, prompting them to "take immediate action to patch ASAP." It also promised to generate a CVE "soon." It is now six days later and a CVE from CrushFTP itself has not yet materialized. Assigning CVEs for vulnerabilities in a timely manner is important for defenders so they can easily track and prioritize the issues affecting their IT estate. Withholding them can lead to confusion and delays for customers. CrushFTP's own ad...
CrushFTP CEO's feisty response to VulnCheck's CVE for critical make-me-admin bug
The Register
·Connor Jones
·Published Mar 27, 2025
·Updated
Affected Software
5 affected components
CrushFTP CrushFTP=10.8.4
CrushFTP CrushFTP=11.3.1
CrushFTP CrushFTP
CrushFTP CrushFTP=10.8.4
CrushFTP CrushFTP=11.3.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in CrushFTP's file transfer technology and the response of its CEO to the unofficial CVE issued by VulnCheck.
2
What security implications are discussed in the article?
The article highlights a critical 'make-me-admin' bug that poses significant security risks for users of CrushFTP.
3
What products are affected by this vulnerability?
The vulnerability affects CrushFTP versions 10.8.4 and 11.3.1.
4
Who issued the unofficial CVE for this vulnerability?
The unofficial CVE for the vulnerability was issued by VulnCheck.
5
How did CrushFTP's CEO respond to the CVE release?
CrushFTP's CEO expressed displeasure with VulnCheck regarding the release of the unofficial CVE.