{"id":10465,"date":"2025-07-21T12:35:01","date_gmt":"2025-07-21T05:35:01","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=10465"},"modified":"2026-02-05T12:35:12","modified_gmt":"2026-02-05T05:35:12","slug":"lo-hong-zero-day-trong-crushftp-cho-phep-chiem-quyen-admin-qua-giao-dien-web","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/2025\/07\/21\/lo-hong-zero-day-trong-crushftp-cho-phep-chiem-quyen-admin-qua-giao-dien-web\/","title":{"rendered":"L\u1ed7 h\u1ed5ng zero-day trong CrushFTP cho ph\u00e9p chi\u1ebfm quy\u1ec1n admin qua giao di\u1ec7n web"},"content":{"rendered":"<div style=\"text-align: justify\"><b>G\u1ea7n \u0111\u00e2y, nh\u00e0 ph\u00e1t tri\u1ec3n ph\u1ea7n m\u1ec1m CrushFTP &#8211; n\u1ec1n t\u1ea3ng m\u00e1y ch\u1ee7 truy\u1ec1n t\u1ec7p doanh nghi\u1ec7p h\u1ed7 tr\u1ee3 FTP, SFTP, HTTP\/S, \u0111\u00e3 c\u1ea3nh b\u00e1o v\u1ec1 m\u1ed9t l\u1ed7 h\u1ed5ng zero-day nghi\u00eam tr\u1ecdng (CVE\u20112025\u201154309), cho ph\u00e9p tin t\u1eb7c chi\u1ebfm quy\u1ec1n qu\u1ea3n tr\u1ecb (admin) t\u1eeb xa th\u00f4ng qua giao di\u1ec7n web.<\/b><br \/>\n\u200b<\/div>\n<div style=\"text-align: center\"><a class=\"js-lbImage\" style=\"cursor: pointer\" href=\"https:\/\/whitehat.vn\/attachments\/1753070762963-png.17342\/\" target=\"_blank\" rel=\"noopener\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-fancybox=\"lb-thread-18582\" data-caption=\"&lt;h4&gt;1753070762963.png&lt;\/h4&gt;&lt;p&gt;&lt;a href=&quot;https:&amp;#x2F;&amp;#x2F;whitehat.vn&amp;#x2F;threads&amp;#x2F;lo-hong-zero-day-trong-crushftp-cho-phep-chiem-quyen-admin-qua-giao-dien-web.18582&amp;#x2F;#post-44089&quot; class=&quot;js-lightboxCloser&quot;&gt;WhiteHat Team \u00b7 21&amp;#x2F;07&amp;#x2F;2025 l\u00fac 11:17 AM&lt;\/a&gt;&lt;\/p&gt;\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage \" title=\"1753070762963.png\" src=\"https:\/\/whitehat.vn\/data\/attachments\/17\/17677-9c6aea6e8f3ce6af5502acc671ddc650.jpg\" alt=\"1753070762963.png\" width=\"712\" height=\"400\" \/><\/a>\u200b<\/div>\n<div style=\"text-align: justify\">\nL\u1ed7 h\u1ed5ng n\u00e0y \u0111\u01b0\u1ee3c \u0111\u1ecbnh danh l\u00e0 CVE-2025-54309, \u0111\u01b0\u1ee3c \u0111\u00e1nh gi\u00e1 c\u00f3 m\u1ee9c \u0111\u1ed9 nguy hi\u1ec3m cao (CVSS 9,0) v\u00e0 \u0111\u00e3 b\u1ecb khai th\u00e1c m\u1ed9t c\u00e1ch ch\u1ee7 \u0111\u1ed9ng \u00edt nh\u1ea5t t\u1eeb 18\/7\/2025.<\/p>\n<p>CrushFTP l\u00e0 ph\u1ea7n m\u1ec1m m\u00e1y ch\u1ee7 \u0111\u01b0\u1ee3c nhi\u1ec1u t\u1ed5 ch\u1ee9c s\u1eed d\u1ee5ng \u0111\u1ec3 truy\u1ec1n v\u00e0 qu\u1ea3n l\u00fd t\u1ec7p qua c\u00e1c giao th\u1ee9c nh\u01b0 FTP, SFTP, HTTP\/S, nh\u1edd t\u00ednh linh ho\u1ea1t v\u00e0 kh\u1ea3 n\u0103ng b\u1ea3o m\u1eadt cao. Tuy nhi\u00ean, theo c\u1ea3nh b\u00e1o t\u1eeb ch\u00ednh nh\u00e0 ph\u00e1t tri\u1ec3n CrushFTP, m\u1ed9t l\u1ed7 h\u1ed5ng trong giao th\u1ee9c AS2 khi x\u1eed l\u00fd qua HTTP(S) \u0111\u00e3 v\u00f4 t\u00ecnh m\u1edf ra c\u01a1 h\u1ed9i cho tin t\u1eb7c chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n m\u00e1y ch\u1ee7 m\u00e0 kh\u00f4ng c\u1ea7n x\u00e1c th\u1ef1c. D\u00f9 l\u1ed7 h\u1ed5ng n\u00e0y t\u1eebng \u0111\u01b0\u1ee3c v\u00e1 gi\u00e1n ti\u1ebfp trong m\u1ed9t b\u1ea3n c\u1eadp nh\u1eadt v\u00e0o \u0111\u1ea7u th\u00e1ng 7, k\u1ebb t\u1ea5n c\u00f4ng \u0111\u01b0\u1ee3c cho l\u00e0 \u0111\u00e3 \u0111\u1ea3o ng\u01b0\u1ee3c m\u00e3 ngu\u1ed3n v\u00e0 t\u00ecm ra c\u00e1ch khai th\u00e1c c\u1ee5 th\u1ec3 t\u1eeb s\u1ef1 thay \u0111\u1ed5i m\u00e3 tr\u01b0\u1edbc \u0111\u00f3.<\/p>\n<p>Tin t\u1eb7c s\u1eed d\u1ee5ng l\u1ed7 h\u1ed5ng n\u00e0y \u0111\u1ec3 ch\u1ec9nh s\u1eeda ho\u1eb7c t\u1ea1o m\u1edbi t\u00e0i kho\u1ea3n qu\u1ea3n tr\u1ecb h\u1ec7 th\u1ed1ng, trong nhi\u1ec1u tr\u01b0\u1eddng h\u1ee3p l\u00e0 ch\u1ec9nh s\u1eeda t\u00e0i kho\u1ea3n m\u1eb7c \u0111\u1ecbnh v\u1edbi \u0111\u1ecbnh d\u1ea1ng kh\u00f4ng h\u1ee3p l\u1ec7 nh\u01b0ng v\u1eabn ho\u1ea1t \u0111\u1ed9ng \u0111\u01b0\u1ee3c. D\u1ea5u hi\u1ec7u nh\u1eadn di\u1ec7n s\u1edbm bao g\u1ed3m c\u00e1c thay \u0111\u1ed5i \u0111\u00e1ng ng\u1edd trong file MainUsers\/default\/user.XML, nh\u01b0 s\u1ef1 xu\u1ea5t hi\u1ec7n c\u1ee7a c\u00e1c tr\u01b0\u1eddng last_logins b\u1ea5t th\u01b0\u1eddng ho\u1eb7c t\u00e0i kho\u1ea3n admin l\u1ea1 v\u1edbi t\u00ean ng\u1eabu nhi\u00ean. Ngo\u00e0i ra, nh\u1eadt k\u00fd upload\/download c\u00f3 th\u1ec3 ghi nh\u1eadn c\u00e1c h\u00e0nh vi b\u1ea5t th\u01b0\u1eddng n\u1ebfu h\u1ec7 th\u1ed1ng \u0111\u00e3 b\u1ecb x\u00e2m nh\u1eadp.<\/p>\n<p>C\u00e1c phi\u00ean b\u1ea3n b\u1ecb \u1ea3nh h\u01b0\u1edfng l\u00e0 CrushFTP v10 tr\u01b0\u1edbc 10.8.5 v\u00e0 v11 tr\u01b0\u1edbc 11.3.4_23, ph\u00e1t h\u00e0nh tr\u01b0\u1edbc ng\u00e0y 1\/7. Nh\u1eefng h\u1ec7 th\u1ed1ng c\u1eadp nh\u1eadt \u0111\u1ea7y \u0111\u1ee7 ho\u1eb7c c\u00f3 s\u1eed d\u1ee5ng ki\u1ebfn tr\u00fac ph\u00e2n t\u00e1ch v\u1edbi DMZ proxy \u0111\u01b0\u1ee3c cho l\u00e0 an to\u00e0n h\u01a1n,. Tuy nhi\u00ean c\u00e1c chuy\u00ean gia khuy\u1ebfn c\u00e1o r\u1eb1ng DMZ kh\u00f4ng n\u00ean \u0111\u01b0\u1ee3c xem l\u00e0 gi\u1ea3i ph\u00e1p b\u1ea3o v\u1ec7 tuy\u1ec7t \u0111\u1ed1i trong tr\u01b0\u1eddng h\u1ee3p n\u00e0y.<\/p>\n<p>Hi\u1ec7n t\u1ea1i ch\u01b0a c\u00f3 th\u00f4ng tin x\u00e1c th\u1ef1c r\u1eb1ng d\u1eef li\u1ec7u \u0111\u00e3 b\u1ecb \u0111\u00e1nh c\u1eafp hay m\u00e3 \u0111\u1ed9c \u0111\u01b0\u1ee3c c\u00e0i c\u1eafm th\u00f4ng qua cu\u1ed9c t\u1ea5n c\u00f4ng, nh\u01b0ng vi\u1ec7c chi\u1ebfm \u0111\u01b0\u1ee3c quy\u1ec1n qu\u1ea3n tr\u1ecb qua giao di\u1ec7n web m\u1edf ra nhi\u1ec1u nguy c\u01a1 v\u1ec1 r\u00f2 r\u1ec9 d\u1eef li\u1ec7u, c\u00e0i m\u00e3 \u0111\u1ed9c t\u1ed1ng ti\u1ec1n ho\u1eb7c truy c\u1eadp l\u00e2u d\u00e0i tr\u00e1i ph\u00e9p. \u0110\u00e2y l\u00e0 m\u1ed1i lo ng\u1ea1i kh\u00f4ng m\u1edbi, \u0111\u1eb7c bi\u1ec7t khi c\u00e1c h\u1ec7 th\u1ed1ng truy\u1ec1n file doanh nghi\u1ec7p nh\u01b0 MOVEit, GoAnywhere, hay Accellion FTA t\u1eebng b\u1ecb khai th\u00e1c b\u1edfi c\u00e1c nh\u00f3m ransomware l\u1edbn trong nh\u1eefng chi\u1ebfn d\u1ecbch quy m\u00f4 to\u00e0n c\u1ea7u.<\/p>\n<p>\u0110\u1ec3 ph\u00f2ng tr\u00e1nh v\u00e0 \u1ee9ng ph\u00f3, WhiteHat v\u00e0 c\u00e1c chuy\u00ean gia b\u1ea3o m\u1eadt khuy\u1ebfn ngh\u1ecb c\u00e1c qu\u1ea3n tr\u1ecb vi\u00ean h\u1ec7 th\u1ed1ng c\u1ea7n th\u1ef1c hi\u1ec7n ngay nh\u1eefng bi\u1ec7n ph\u00e1p sau:\u200b<\/p><\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">C\u1eadp nh\u1eadt ph\u1ea7n m\u1ec1m l\u00ean phi\u00ean b\u1ea3n CrushFTP v10.8.5_12 ho\u1eb7c v11.3.4_26 tr\u1edf l\u00ean.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">R\u00e0 so\u00e1t file c\u1ea5u h\u00ecnh ng\u01b0\u1eddi d\u00f9ng (default\/user.XML) v\u00e0 kh\u00f4i ph\u1ee5c t\u1eeb b\u1ea3n sao l\u01b0u tr\u01b0\u1edbc ng\u00e0y 16\/7, n\u1ebfu nghi ng\u1edd b\u1ecb ch\u1ec9nh s\u1eeda.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">X\u00f3a t\u00e0i kho\u1ea3n &#8220;default&#8221;, \u0111\u1ec3 ph\u1ea7n m\u1ec1m t\u1ef1 t\u1ea1o l\u1ea1i t\u1eeb m\u1eb7c \u0111\u1ecbnh an to\u00e0n.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Ki\u1ec3m tra log upload\/download \u0111\u1ec3 ph\u00e1t hi\u1ec7n ho\u1ea1t \u0111\u1ed9ng b\u1ea5t th\u01b0\u1eddng.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Gi\u1edbi h\u1ea1n truy c\u1eadp qu\u1ea3n tr\u1ecb b\u1eb1ng c\u00e1ch thi\u1ebft l\u1eadp whitelist \u0111\u1ecba ch\u1ec9 IP tin c\u1eady.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">C\u00e2n nh\u1eafc tri\u1ec3n khai m\u00f4 h\u00ecnh DMZ, nh\u01b0ng kh\u00f4ng n\u00ean xem \u0111\u00e2y l\u00e0 gi\u1ea3i ph\u00e1p duy nh\u1ea5t.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">K\u00edch ho\u1ea1t t\u00ednh n\u0103ng t\u1ef1 \u0111\u1ed9ng c\u1eadp nh\u1eadt ph\u1ea7n m\u1ec1m v\u00e0 theo d\u00f5i th\u00f4ng tin c\u1ea3nh b\u00e1o b\u1ea3o m\u1eadt th\u01b0\u1eddng xuy\u00ean.\u200b<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">S\u1ef1 c\u1ed1 l\u1ea7n n\u00e0y ti\u1ebfp t\u1ee5c cho th\u1ea5y c\u00e1c h\u1ec7 th\u1ed1ng truy\u1ec1n t\u1ea3i file doanh nghi\u1ec7p \u0111ang l\u00e0 m\u1ee5c ti\u00eau h\u1ea5p d\u1eabn v\u1edbi gi\u1edbi t\u1ed9i ph\u1ea1m m\u1ea1ng. Trong b\u1ed1i c\u1ea3nh c\u00e1c v\u1ee5 t\u1ea5n c\u00f4ng v\u00e0o ph\u1ea7n m\u1ec1m trung gian ng\u00e0y c\u00e0ng gia t\u0103ng, vi\u1ec7c c\u1eadp nh\u1eadt ph\u1ea7n m\u1ec1m th\u01b0\u1eddng xuy\u00ean v\u00e0 ki\u1ec3m tra c\u1ea5u h\u00ecnh h\u1ec7 th\u1ed1ng tr\u1edf n\u00ean quan tr\u1ecdng h\u01a1n bao gi\u1edd h\u1ebft. C\u00e1c t\u1ed5 ch\u1ee9c c\u1ea7n nhanh ch\u00f3ng h\u00e0nh \u0111\u1ed9ng \u0111\u1ec3 b\u1ea3o v\u1ec7 t\u00e0i s\u1ea3n s\u1ed1 v\u00e0 d\u1eef li\u1ec7u kh\u00e1ch h\u00e0ng tr\u01b0\u1edbc khi qu\u00e1 mu\u1ed9n.\u200b<\/div>\n<div style=\"text-align: right\"><b><i>Theo WhiteHat t\u1ed5ng h\u1ee3p<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/lo-hong-zero-day-trong-crushftp-cho-phep-chiem-quyen-admin-qua-giao-dien-web.18582\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/lo-hong-zero-day-trong-crushftp-cho-phep-chiem-quyen-admin-qua-giao-dien-web.18582\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>G\u1ea7n \u0111\u00e2y, nh\u00e0 ph\u00e1t tri\u1ec3n ph\u1ea7n m\u1ec1m CrushFTP &#8211; n\u1ec1n t\u1ea3ng m\u00e1y ch\u1ee7 truy\u1ec1n t\u1ec7p doanh nghi\u1ec7p h\u1ed7 tr\u1ee3 FTP, SFTP, HTTP\/S, \u0111\u00e3 c\u1ea3nh b\u00e1o v\u1ec1 m\u1ed9t l\u1ed7 h\u1ed5ng zero-day nghi\u00eam tr\u1ecdng (CVE\u20112025\u201154309), cho ph\u00e9p tin t\u1eb7c chi\u1ebfm quy\u1ec1n qu\u1ea3n tr\u1ecb (admin) t\u1eeb xa th\u00f4ng qua giao di\u1ec7n web. \u200b \u200b L\u1ed7 h\u1ed5ng n\u00e0y \u0111\u01b0\u1ee3c [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-10465","post","type-post","status-publish","format-standard","hentry","category-tin-tuc-cua-vien"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10465","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=10465"}],"version-history":[{"count":0,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10465\/revisions"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=10465"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=10465"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=10465"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}