vulns.co
/
GKData.io MCP

Back to CVEs

CVE-2025-31161 - CrushFTP authentication bypass

AWS4-HMAC authorization handling can permit authentication bypass and takeover of a known or guessable account, including a privileged account, when the relevant DMZ proxy protection is not used.

Tags: auth-bypass, account-takeover, crushftp, exploited

Product
CrushFTP 10 before 10.8.4 and 11 before 11.3.1
Severity
critical (CVSS 9.8)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published / added
2025-04-03
Signals
CISA KEV

References and evidence