Exploited Vulnerabilities Daily
🌐 English

Home › CrushFTP

CVE-2025-54309: CrushFTP CrushFTP

EPSS95.1%No. 364 of 1739 in KEV
CVE year2025listed the same year
Same vendor in KEV3
Same product3
FieldValue
VendorCrushFTP
ProductCrushFTP
NameCrushFTP Unprotected Alternate Channel Vulnerability
Added to KEV2025-07-22
US federal due date2025-08-12
Ransomware useUnknown
CWECWE-420

CISA description

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2025-31161CrushFTP CrushFTP2025-04-0799.9%Known
CVE-2024-4040CrushFTP CrushFTP2024-04-2499.5%Unknown

NVD — CVE-2025-54309

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A CrushFTP CrushFTP vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-22.