216.73.216.6

CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation

· Published 05/04/2025 07:55 · Modified 07/04/2025 08:34

Export JSON

Essential information

Published
05/04/2025 07:55
Modified
07/04/2025 08:34
Tags
2025-04-05 CVE-2025-31161 anydesk authentication bypass crushftp meshcentral meshcentral agent telegram bot
Related entities
10 techniques (mitre), 3 malware, 4 others

Description

A critical vulnerability () in managed file transfer software allows attackers to bypass authentication and gain admin-level access. Affecting versions 10.0.0-10.8.3 and 11.0.0-11.3.0, the flaw enables unauthorized actions, including data retrieval and administrative control. Exploitation has been observed since March 30, 2025, with ~1,500 vulnerable instances exposed. Post-exploitation activities include creating backdoor accounts, deploying agents, and using for remote access. A -based malware was also identified. The vulnerability stems from improper S3 authorization header processing and can be exploited with a simple HTTP request. Immediate patching to versions 11.3.1+ or 10.8.4+ is strongly recommended.

External references