{"id":11461,"date":"2025-07-21T12:32:35","date_gmt":"2025-07-21T05:32:35","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=11461"},"modified":"2026-06-25T10:00:05","modified_gmt":"2026-06-25T03:00:05","slug":"zero-day-vulnerability-in-crushftp-allows-admin-permissions-over-web-interface","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/en\/2025\/07\/21\/zero-day-vulnerability-in-crushftp-allows-admin-permissions-over-web-interface\/","title":{"rendered":"Zero-day vulnerability in CrushFTP allows admin permissions over web interface"},"content":{"rendered":"<div style=\"text-align: justify\"><b>Recently, the software developer CrushFTP \u2013 the FTP &#8211; supported enterprise file transfer server platform, SFTp, HTTP\/S, warned of a serious zero &#8211; day vulnerability (CVE 2025 54309), which allowed hackers to take remote administration over the web interface.<\/b><br \/>\n\u200b<\/div>\n<div style=\"text-align: center\"><a class=\"js-lbImage\" style=\"cursor: pointer\" href=\"https:\/\/whitehat.vn\/attachments\/1753070762963-png.17342\/\" target=\"_blank\" rel=\"noopener\" data-caption=\"&lt;h4&gt;1753070762963.png&lt;\/h4&gt;&lt;p&gt;&lt;a href=&quot;https:&amp;#x2F;&amp;#x2F;whitehat.vn&amp;#x2F;threads&amp;#x2F;lo-hong-zero-day-trong-crushftp-cho-phep-chiem-quyen-admin-qua-giao-dien-web.18582&amp;#x2F;#post-44089&quot; class=&quot;js-lightboxCloser&quot;&gt;WhiteHat Team \u00b7 21&amp;#x2F;07&amp;#x2F;2025 l\u00fac 11:17 AM&lt;\/a&gt;&lt;\/p&gt;\" data-fancybox=\"lb-thread-18582\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1753070762963.png\" src=\"https:\/\/whitehat.vn\/data\/attachments\/17\/17677-9c6aea6e8f3ce6af5502acc671ddc650.jpg\" alt=\"1753070762963.png\" width=\"712\" height=\"400\" \/><\/a>\u200b<\/div>\n<div style=\"text-align: justify\">\n<p>The breach, designated CVE-2025-54309, was rated high-level hazardous (CVSS 9.0) and has been actively exploited since at least July 18,2015.<\/p>\n<p>CrushFTP is server software used by many organizations to transmit and manage files over protocols such as FTP, SFTp, HTTP\/S, due to its flexibility and high security. However, according to warnings from CrushFTP developers themselves, a vulnerability in the AS2 protocol when processed via HTTP(S) inadvertently opened up the opportunity for hackers to take control of the server without authentication. Although the vulnerability had been indirectly patched in an update in early July, the attacker allegedly reversed the source code and found specific exploit from the previous code change.<\/p>\n<p>Hackers use this vulnerability to modify or create new system administrator accounts, in many cases modifying default accounts with invalid but working formats. Early identifiers include suspicious changes in the MainUsers\/default\/user.XML file, such as the appearance of unusual last logins fields or strange admin accounts with random names. In addition, the upload\/download log may record unusual behavior if the system has been compromised.<\/p>\n<p>The affected versions were CrushFTP v10 before 10.8.5 and v11 before 11.3.4 23, released before July 1. Systems that are fully updated or that use a demultiplexing architecture with DMZ proxies are considered safer. However experts recommend that DMZs should not be considered as absolute protection in this case.<\/p>\n<p>There is currently no confirmation that the data was stolen or that the malware was planted through the attack, but gaining control over the web interface opens up many risks of data leakage, blackmail, or unauthorized long &#8211; term access. This is a non-new concern, especially as corporate file transfer systems such as MOVEit, GoAnywhere, and Accellion FTA have been exploited by large groups of ransomware attackers in global campaigns.<\/p>\n<p>For prevention and response, WhiteHat and security experts recommend that system administrators take the following measures immediately:<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Update the software to CrushFTP v10.8.5 12 or v11.3.4 26 or later.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Review the user configuration file (default\/user.XML) and restore it from a backup before July 16, if it is suspected to be modified.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Delete the &#8220;default&#8221; account, to allow the software to safely remake the default.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Check log upload\/download for unusual activity.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Limit administrative access by setting a trusted IP address whitelist.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Consider implementing a DMZ model, but don&#8217;t consider it the only solution.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Enable automatic software updates and monitor security warnings regularly.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">This incident further showed that corporate file transmission systems are attractive targets for cybercriminals. Amid increasing attacks on middleware, regular software updates and system configuration checks become more important than ever. Organizations need to act quickly to protect digital assets and customer data before it&#8217;s too late.<\/div>\n<div style=\"text-align: right\"><b><i>According to Synthetic WhiteHat<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/lo-hong-zero-day-trong-crushftp-cho-phep-chiem-quyen-admin-qua-giao-dien-web.18582\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/lo-hong-zero-day-trong-crushftp-cho-phep-chiem-quyen-admin-qua-giao-dien-web.18582\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Recently, the software developer CrushFTP \u2013 the FTP &#8211; supported enterprise file transfer server platform, SFTp, HTTP\/S, warned of a serious zero &#8211; day vulnerability (CVE 2025 54309), which allowed hackers to take remote administration over the web interface. \u200b \u200b The breach, designated CVE-2025-54309, was rated high-level hazardous (CVSS 9.0) and has been actively [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[351],"tags":[],"class_list":["post-11461","post","type-post","status-publish","format-standard","hentry","category-news-announcements"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11461","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=11461"}],"version-history":[{"count":2,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11461\/revisions"}],"predecessor-version":[{"id":11650,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11461\/revisions\/11650"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=11461"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=11461"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=11461"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}