Skip to content
COOEY

FAIL › dossier

CrushFTP

VENDOR

· dossier confidence 67%

CrushFTP has experienced multiple critical and high-severity vulnerabilities in recent years, including authentication bypass and remote code execution flaws, raising concerns about the security of their platform and potential exploitation risks.

PROFILE
CategoryCybersecurityWhat they doCrowdStrike Holdings provides cybersecurity solutions in the United States and internationally, offering cloud-delivered protection of endpoints, cloud workloads, identity, and data through a software as a service (SaaS) subscription-based model.Ownershippublic Websitehttps://stockanalysis.com/stocks/crwd/company/ ↗
SECURITY POSTURE

CrushFTP has demonstrated a history of critical and high-severity vulnerabilities, indicating a potential weakness in their security development practices.

Notable failures
  • CVE-2025-31161: Unauthenticated account compromise via HTTP headers
  • CVE-2025-54309: Unprotected HTTPS channel for admin access
  • CVE-2024-4040: VFS sandbox escape allowing arbitrary code execution
Patterns: Critical vulnerabilities related to authentication bypass; Remote code execution (RCE) vulnerabilities
FAILURE HISTORY · 6
DATEEVENTSEVSUMMARY
2025-04-07 CVE-2025-31161 critical CrushFTP allows unauthenticated attackers to bypass authentication via HTTP headers, enabling full account compromise.
2025-04-07 CVE-2025-31161 critical CrushFTP allows unauthenticated attackers to bypass authentication via HTTP headers, enabling full account compromise.
2025-07-22 CVE-2025-54309 high CrushFTP admin access via unprotected HTTPS channel
2025-07-22 CVE-2025-54309 high CrushFTP admin access via unprotected HTTPS channel
2024-04-24 CVE-2024-4040 high CrushFTP's VFS sandbox escape vulnerability (CVE-2024-4040) allows remote attackers to bypass sandbox restrictions and execute arbitrary code.
2024-04-24 CVE-2024-4040 high CrushFTP's VFS sandbox escape vulnerability (CVE-2024-4040) allows remote attackers to bypass sandbox restrictions and execute arbitrary code.
Open questions: What is the current status of remediation for the identified vulnerabilities? · What security development lifecycle (SDLC) practices are in place to prevent future vulnerabilities? · What is the ownership structure of CrushFTP?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-03 03:58:00.611208+00:00