← Back to advisories & guidance
July 24, 2025
CERT-EU
Advisory
Summary
CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers [2, 3]. Threat actors were first detected exploiting the vulnerability on July 18th at 9AM CST, though it may have begun in the early hours of the previous day [1]. The attack occurs via the software’s web interface in versions prior to CrushFTP v10.8.5 and CrushFTP v11.3.4_23. It is unclear when these versions were released, but CrushFTP says Enterprise customers using a DMZ CrushFTP instance to isolate their main server are not believed to be affected by this vulnerability. We believe this bug was in builds prior to July 1st time period roughly. . . the latest versions of CrushFTP already have the issue patched. The attack vector was HTTP(S) for how they could exploit the server.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
Extracted from the publication text. Each CVE links to its tracked detail page.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.