Known vulnerability record

CVE-2025-31161

CrushFTP Authentication Bypass Vulnerability

Stable IDcve:CVE-2025-31161Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

CrushFTP Authentication Bypass Vulnerability

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

Keep the signals separate

CVSS severitycriticalScore 9.8 · source mitre
EPSS probability99.9%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2025-04-07
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2025-04-03
CVE modified
2025-10-21
KEV date added
2025-04-07
Dataset fetched
2026-08-21T03:55:10.390Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.