CVE-2025-31161 - CrushFTP authentication bypass
AWS4-HMAC authorization handling can permit authentication bypass and takeover of a known or guessable account, including a privileged account, when the relevant DMZ proxy protection is not used.
Tags: auth-bypass, account-takeover, crushftp, exploited
- Product
- CrushFTP 10 before 10.8.4 and 11 before 11.3.1
- Severity
- critical (CVSS 9.8)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Published / added
- 2025-04-03
- Signals
- CISA KEV