CVE Chaos: CrushFTP’s Vulnerability Drama Unfolds with a Side of Confusion and Blame
CrushFTP’s critical vulnerability saga unfolds with two CVE numbers and a dash of drama. VulnCheck jumps the gun with CVE-2025-2825, while CrushFTP waits for CVE-2025-31161. Amidst all this, hackers exploit the flaw faster than popcorn in a microwave. The question remains: who’s the real bad actor here?

Hot Take:
In the world of cybersecurity, it’s not unusual for things to get a bit “crushy.” While CrushFTP may have been feeling the pressure, the real crush seems to be between two CVE numbers, each vying for the spotlight in a vulnerability soap opera that’s more dramatic than your average telenovela. Who knew numbers could be so contentious?
Key Points:
- A critical vulnerability in CrushFTP versions 10 and 11 allows threat actors to bypass authentication.
- VulnCheck assigned CVE-2025-2825, while CrushFTP argues CVE-2025-31161 is the “real CVE.”
- Outpost24 responsibly disclosed the flaw, planning a 90-day non-disclosure period.
- Exploitation attempts have been observed, with IPs launching attacks decreasing.
- Hundreds of vulnerable CrushFTP instances remain worldwide, including in the US.
Already a member? Log in here