Skip to content
COOEY

EXPOSURES › CVE-2025-31161

CVE-2025-31161

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-04-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-31161 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatched

CrushFTP allows unauthenticated attackers to bypass authentication via HTTP headers, enabling full account compromise.

An authentication bypass in CrushFTP lets remote attackers authenticate as any known or guessable user without credentials, leading to full system compromise. DIBs must patch immediately and audit HTTP header handling, as this flaw is actively exploited in the wild and linked to ransomware.

Shame score — A critical, actively exploited authentication bypass that enables full account compromise without requiring any credentials, directly linking to ransomware attacks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.