CVE-2025-31161
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-31161 is a vulnerability affecting CrushFTP versions 10 before 10.8.4 and 11 before 11.3.1. It allows an attacker to bypass authentication and take over the crushadmin account, potentially leading to a full system compromise. The issue stems from a race condition in the AWS4-HMAC authorization method of the HTTP component of the FTP server. The server first verifies the existence of the user without requiring a password, enabling unauthenticated access. However, this can be exploited by sending a mangled AWS4-HMAC header, causing an index-out-of-bounds error that halts the session cleanup process. This combination of vulnerabilities makes it simple for attackers to authenticate as any known or guessable user, including administrative accounts. The vulnerability was exploited in the wild in March and April 2025.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- CrushFTP