Skip to main content

CrushFTP security briefs

1 published alerts for CrushFTP products and services.

Actively exploited (KEV)Ransomware

CVE-2025-31161

CrushFTP Authentication Bypass Vulnerability

CrushFTP CrushFTP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-31161). CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise. CISA remediation due date: 2025-04-28. If you need help checking exposure, call (864) 335-9223.