A critical CrushFTP authentication bypass flaw, initially tracked as CVE-2025-2825 and later re-tracked as CVE-2025-31161, allows unauthenticated remote attackers to log in as valid users by sending a crafted S3-compatible Authorization header. The bug affects versions 10.0.0–10.8.3 and 11.0.0–11.3.0, and stems from flawed authentication logic in loginCheckHeaderAuth() that can skip password verification when processing AWS4-HMAC-style credentials. Researchers reported that an attacker may need only a username in the Credential field and a syntactically valid CrushAuth cookie format, without successful signature validation, to gain unauthorized access.
Security teams reported active exploitation against internet-exposed CrushFTP servers, with Shadowserver observing dozens of attack attempts in the wild. CrushFTP addressed the issue in 10.8.4 and 11.3.1, including changes to properly validate passwords and a default-disabled setting to block the vulnerable path; defenders were urged to upgrade immediately, restrict external access, or enable DMZ mode where patching is not yet possible. ProjectDiscovery also released a Nuclei detection template that checks for successful user-list retrieval via the bypass, underscoring the need to identify exposed and vulnerable instances quickly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that the CrushFTP authentication bypass was being actively exploited in the wild. The advisory cited Shadowserver observations of dozens of exploitation attempts against internet-exposed CrushFTP servers.
ProjectDiscovery published technical analysis of the CrushFTP authentication bypass, including root-cause details, a proof of concept, and a Nuclei detection template. The post also noted that the issue was initially tracked as CVE-2025-2825 and later re-tracked as CVE-2025-31161 after NIST rejected the original CVE ID.
CrushFTP remediated a critical authentication bypass affecting versions 10.0.0–10.8.3 and 11.0.0–11.3.0. The fix was released in version 10.8.4 for the 10.x branch and 11.3.1 for the 11.x branch, with DMZ mode suggested as a mitigation if patching was not possible.
The vulnerability was published in the NVD as part of the disclosure timeline. ProjectDiscovery notes this publication occurred on March 26, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.