CVE-2025-54309
KEVCrushFTP Unprotected Alternate Channel Vulnerability
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
Comprehensive Technical Analysis of CVE-2025-54309
1. Vulnerability Assessment and Severity Evaluation
CVE ID: CVE-2025-54309 CVSS Score: 9
The vulnerability in CrushFTP versions 10 before 10.8.5 and 11 before 11.3.4_23 involves a mishandling of AS2 (Applicability Statement 2) validation. This flaw allows remote attackers to obtain administrative access via HTTPS when the DMZ proxy feature is not used. The CVSS score of 9 indicates a critical severity, reflecting the potential for significant impact on affected systems.
2. Potential Attack Vectors and Exploitation Methods
Attack Vectors:
- Remote Exploitation: The vulnerability can be exploited remotely over HTTPS, making it accessible to attackers from anywhere in the world.
- AS2 Validation Bypass: The core issue lies in the improper handling of AS2 validation, which can be bypassed to escalate privileges.
Exploitation Methods:
- Credential Theft: Attackers could exploit this vulnerability to steal administrative credentials.
- Unauthorized Access: Once admin access is obtained, attackers can perform various malicious activities, including data exfiltration, system configuration changes, and further exploitation of connected systems.
3. Affected Systems and Software Versions
Affected Software:
- CrushFTP 10 versions before 10.8.5
- CrushFTP 11 versions before 11.3.4_23
Conditions:
- The DMZ proxy feature must not be in use for the vulnerability to be exploitable.
4. Recommended Mitigation Strategies
Immediate Actions:
- Patching: Upgrade to CrushFTP 10.8.5 or later, or CrushFTP 11.3.4_23 or later.
- Enable DMZ Proxy: If upgrading is not immediately feasible, enable the DMZ proxy feature to mitigate the risk.
Long-Term Strategies:
- Regular Updates: Ensure that all software, especially critical systems like CrushFTP, are regularly updated to the latest versions.
- Network Segmentation: Implement network segmentation to limit the exposure of critical systems.
- Monitoring: Enhance monitoring and logging to detect any unusual activities that may indicate an exploitation attempt.
5. Impact on Cybersecurity Landscape
Broader Implications:
- Widespread Use: CrushFTP is widely used in various industries for secure file transfers, making this vulnerability a significant concern.
- Exploitation in the Wild: The fact that this vulnerability has been exploited in the wild underscores the urgency for immediate mitigation.
- Trust and Reputation: Organizations relying on CrushFTP may face trust and reputational risks if their systems are compromised.
6. Technical Details for Security Professionals
Technical Insights:
- AS2 Protocol: Understanding the AS2 protocol is crucial for identifying how the validation process can be bypassed. AS2 is commonly used for secure and reliable file transfers over the internet.
- DMZ Proxy Feature: The DMZ proxy feature acts as an additional layer of security by isolating the CrushFTP server from direct internet exposure.
- Detection and Response: Implement intrusion detection systems (IDS) and intrusion prevention systems (IPS) to detect and respond to any suspicious activities related to AS2 validation.
Recommendations for Security Teams:
- Incident Response Plan: Develop and update incident response plans to include scenarios related to this vulnerability.
- Security Awareness: Conduct training sessions to educate staff on the importance of timely patching and the risks associated with unpatched systems.
- Threat Intelligence: Leverage threat intelligence feeds to stay informed about emerging threats and vulnerabilities.
Conclusion
CVE-2025-54309 represents a critical vulnerability in CrushFTP that requires immediate attention. Organizations using affected versions should prioritize patching and consider enabling the DMZ proxy feature as a temporary mitigation. Enhanced monitoring, regular updates, and robust incident response plans are essential for maintaining a strong cybersecurity posture in the face of such threats.