Loading HuntDB...

CVE-2025-2825

UNKNOWN
Published 2025-03-26T15:58:14.218Z
Actions:
No CVSS data available

Description

No description available

Available Exploits

CrushFTP - Authentication Bypass

CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability that may result in unauthenticated access. Remote and unauthenticated HTTP requests to CrushFTP may allow attackers to gain unauthorized access.

ID: CVE-2025-2825
Author: parthmalhotraIce3manDhiyaneshDkpdresearch Critical

Related News

Imperva Customers Are Protected Against CVE-2025-31161 in CrushFTP

Introduction A critical security vulnerability, identified as CVE-2025-31161 (previously tracked as CVE-2025-2825), has been discovered in CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0. This flaw allows unauthenticated remote attackers to …

Imperva.com 2025-04-10 19:05
Attackers are targeting CrushFTP vulnerability with public PoC (CVE-2025-2825)

Exploitation attempts targeting the CVE-2025-2825 vulnerability on internet-facing CrushFTP instances are happening, the Shadowserver Foundation has shared on Monday, and the attackers have been leveraging publicly available PoC exploit code. What can be done…

Help Net Security 2025-04-01 15:35
CrushFTP CVE-2025-2825 flaw actively exploited in the wild

Attackers exploit CrushFTP CVE-2025-2825 flaw, enabling unauthenticated access to unpatched devices using public proof-of-concept code. Threat actors are exploiting a critical authentication bypass vulnerability, tracked as CVE-2025-2825, in the CrushFTP file…

Securityaffairs.com 2025-04-01 14:09
Published: 2025-03-26T15:58:14.218Z
Last Modified: 2025-04-04T19:48:00.370Z
Copied to clipboard!