Skip to content
COOEY

EXPOSURES › CVE-2025-54309

CVE-2025-54309

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-07-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-54309 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

CrushFTP admin access via unprotected HTTPS channel

CrushFTP, a file transfer product, exposed admin access through an unprotected HTTPS channel, allowing remote attackers to gain control without authentication. This vulnerability was actively exploited in the wild, posing a high risk to DIB organizations.

Shame score — Active exploitation in the wild and failure to use DMZ proxy feature, leading to unauthorized admin access.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.