CVE-2025-31161 is a critical vulnerability actively exploited in the wild, which has received widespread attention due to its severity and the prevalence of CrushFTP in enterprise environments. The vulnerability has a CVSS score of 9.8, highlighting its low complexity and high impact.
| Product | CrushFTP |
| Date | 2025-04-15 15:17:47 |
| Information |
|
Technical Summary
CVE-2025-31161 affects CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0. It originates from a flawed implementation of S3-style authentication in the loginCheckHeaderAuth() function.
The vulnerability is rooted in the improper use of a boolean flag called lookup_user_pass. This flag—intended to determine whether the server should use a stored password or one provided in a request—is passed downstream as anyPass to the authentication handler. When anyPass is set to true, password validation is completely bypassed.
An attacker can exploit this vulnerability by sending a specially crafted request with:
- An
Authorizationheader structured as:
Authorization: AWS4-HMAC-SHA256 Credential=crushadmin/ - A
CrushAuthcookie in the format:
CrushAuth=1743113839553_vD96EZ70ONL6xAd1DAJhXMZYMn1111 - A
c2fparameter that matches the last 4 characters of the cookie.
Due to poor validation logic (e.g., parsing only up to the slash / in the Credential= field and failing to verify the signature), the attacker can bypass authentication and gain full access to the server. This includes the ability to:
- View and exfiltrate sensitive files
- Upload malicious files
- Create or modify administrator users
- Completely compromise the CrushFTP server and move laterally within the internal infrastructure
Recommendations
CrushFTP has released patched versions 10.8.4+ and 11.3.1+ that fix the authentication logic and prevent this bypass. All administrators using affected versions are strongly urged to proceed with the update immediately.
In the meantime, consider:
- Blocking access to the CrushFTP interface from untrusted networks
- Analyzing logs for suspicious access attempts using S3-style headers
- Using the Nuclei detection template provided by ProjectDiscovery to scan for vulnerable instances
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
