Critical Authentication Bypass in CrushFTP (CVE-2025-31161)

ISGroup Cybersecurity

CVE-2025-31161 is a critical vulnerability actively exploited in the wild, which has received widespread attention due to its severity and the prevalence of CrushFTP in enterprise environments. The vulnerability has a CVSS score of 9.8, highlighting its low complexity and high impact.

ProductCrushFTP
Date2025-04-15 15:17:47
Information
  • Fix Available
  • Active Exploitation

Technical Summary

CVE-2025-31161 affects CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0. It originates from a flawed implementation of S3-style authentication in the loginCheckHeaderAuth() function.

The vulnerability is rooted in the improper use of a boolean flag called lookup_user_pass. This flag—intended to determine whether the server should use a stored password or one provided in a request—is passed downstream as anyPass to the authentication handler. When anyPass is set to true, password validation is completely bypassed.

An attacker can exploit this vulnerability by sending a specially crafted request with:

  • An Authorization header structured as:
    Authorization: AWS4-HMAC-SHA256 Credential=crushadmin/
  • A CrushAuth cookie in the format:
    CrushAuth=1743113839553_vD96EZ70ONL6xAd1DAJhXMZYMn1111
  • A c2f parameter that matches the last 4 characters of the cookie.

Due to poor validation logic (e.g., parsing only up to the slash / in the Credential= field and failing to verify the signature), the attacker can bypass authentication and gain full access to the server. This includes the ability to:

  • View and exfiltrate sensitive files
  • Upload malicious files
  • Create or modify administrator users
  • Completely compromise the CrushFTP server and move laterally within the internal infrastructure

Recommendations

CrushFTP has released patched versions 10.8.4+ and 11.3.1+ that fix the authentication logic and prevent this bypass. All administrators using affected versions are strongly urged to proceed with the update immediately.

In the meantime, consider:

  • Blocking access to the CrushFTP interface from untrusted networks
  • Analyzing logs for suspicious access attempts using S3-style headers
  • Using the Nuclei detection template provided by ProjectDiscovery to scan for vulnerable instances

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert