Security
Loading…

CVE-2025-54309

UNKNOWNKnown Exploited
Description

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.

Timeline
Published:July 22nd, 2025 12:00 AM
Last modified:July 22nd, 2025 12:00 AM
Added to KEV:July 22nd, 2025
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

CrushFTP

Products

CrushFTP
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute