CVE-2025-54309
CrushFTP Authentication Bypass Vulnerability
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23 mishandles AS2 validation when the DMZ proxy feature is not used and consequently allows remote attackers to obtain admin access via HTTPS.
Unauthenticated remote attackers can bypass authentication on the affected CrushFTP device leading to unauthorized access.
Mitigations
- Reference the vendor advisory for mitigation and update instructions.
Rapid Response N-Day Testing

References
🔗 CVE-2025-54309Â
🔗 Vendor AdvisoryÂ