CVE Chaos: CrushFTP’s Vulnerability Drama Unfolds with a Side of Confusion and Blame

CrushFTP’s critical vulnerability saga unfolds with two CVE numbers and a dash of drama. VulnCheck jumps the gun with CVE-2025-2825, while CrushFTP waits for CVE-2025-31161. Amidst all this, hackers exploit the flaw faster than popcorn in a microwave. The question remains: who’s the real bad actor here?

Pro Dashboard

Hot Take:

In the world of cybersecurity, it’s not unusual for things to get a bit “crushy.” While CrushFTP may have been feeling the pressure, the real crush seems to be between two CVE numbers, each vying for the spotlight in a vulnerability soap opera that’s more dramatic than your average telenovela. Who knew numbers could be so contentious?

Key Points:

  • A critical vulnerability in CrushFTP versions 10 and 11 allows threat actors to bypass authentication.
  • VulnCheck assigned CVE-2025-2825, while CrushFTP argues CVE-2025-31161 is the “real CVE.”
  • Outpost24 responsibly disclosed the flaw, planning a 90-day non-disclosure period.
  • Exploitation attempts have been observed, with IPs launching attacks decreasing.
  • Hundreds of vulnerable CrushFTP instances remain worldwide, including in the US.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?