Hackers Exploit Critical CrushFTP Zero-Day to Compromise Servers

1 min read
Source: The Hacker News
Hackers Exploit Critical CrushFTP Zero-Day to Compromise Servers
Photo: The Hacker News
TL;DR Summary

A critical flaw in CrushFTP (CVE-2025-54309) is actively exploited, allowing remote attackers to gain admin access on unpatched servers, especially affecting sensitive environments. The vulnerability, present in versions before 10.8.5 and 11.3.4_23, involves mishandling AS2 validation and can be exploited via HTTP(S). Organizations are advised to review logs, restrict IPs, and update to mitigate risks, as multiple CVEs have targeted CrushFTP recently.

Share this article

Reading Insights

Total Reads

0

Unique Readers

3

Time Saved

3 min

vs 3 min read

Condensed

89%

59062 words

Want the full story? Read the original article

Read on The Hacker News