FAIL › dossier
CrushFTP
VENDOR· dossier confidence 67%
CrushFTP has experienced multiple critical and high-severity vulnerabilities in recent years, including authentication bypass and remote code execution flaws, raising concerns about the security of their platform and potential exploitation risks.
PROFILE
CategoryCybersecurityWhat they doCrowdStrike Holdings provides cybersecurity solutions in the United States and internationally, offering cloud-delivered protection of endpoints, cloud workloads, identity, and data through a software as a service (SaaS) subscription-based model.Ownershippublic
Websitehttps://stockanalysis.com/stocks/crwd/company/ ↗
SECURITY POSTURE
CrushFTP has demonstrated a history of critical and high-severity vulnerabilities, indicating a potential weakness in their security development practices.
Notable failures
- CVE-2025-31161: Unauthenticated account compromise via HTTP headers
- CVE-2025-54309: Unprotected HTTPS channel for admin access
- CVE-2024-4040: VFS sandbox escape allowing arbitrary code execution
Patterns: Critical vulnerabilities related to authentication bypass; Remote code execution (RCE) vulnerabilities
FAILURE HISTORY · 6
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-04-07 | CVE-2025-31161 | critical | CrushFTP allows unauthenticated attackers to bypass authentication via HTTP headers, enabling full account compromise. |
| 2025-04-07 | CVE-2025-31161 | critical | CrushFTP allows unauthenticated attackers to bypass authentication via HTTP headers, enabling full account compromise. |
| 2025-07-22 | CVE-2025-54309 | high | CrushFTP admin access via unprotected HTTPS channel |
| 2025-07-22 | CVE-2025-54309 | high | CrushFTP admin access via unprotected HTTPS channel |
| 2024-04-24 | CVE-2024-4040 | high | CrushFTP's VFS sandbox escape vulnerability (CVE-2024-4040) allows remote attackers to bypass sandbox restrictions and execute arbitrary code. |
| 2024-04-24 | CVE-2024-4040 | high | CrushFTP's VFS sandbox escape vulnerability (CVE-2024-4040) allows remote attackers to bypass sandbox restrictions and execute arbitrary code. |
DOSSIER SOURCES
- CrowdStrike Holdings (CRWD) Company Profile & Description · stockanalysis.com
- George Kurtz - Forbes · www.forbes.com
- CRITICAL: Vulnerable HTTP Report - Shadowserver · www.shadowserver.org
Open questions: What is the current status of remediation for the identified vulnerabilities? · What security development lifecycle (SDLC) practices are in place to prevent future vulnerabilities? · What is the ownership structure of CrushFTP?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-03 03:58:00.611208+00:00