Critical Zero-Day in CrushFTP Under Active Attack: Admin Access at Risk!

Listen to this Post

Featured Image

Introduction: Why This Flaw Is a Big Deal

A new zero-day vulnerability in CrushFTP—a secure file transfer platform used by governments, enterprises, and healthcare providers—has been exposed and is already being exploited in the wild. Identified as CVE-2025-54309 and rated 9.0 on the CVSS scale, this flaw allows remote attackers to gain unauthorized administrative access via HTTPS under specific conditions. What makes this vulnerability alarming is that it’s being weaponized even before the public was fully aware—highlighting a dangerous new trend in cyber warfare.

Below, we break down the full scope of the issue, what CrushFTP says, what security analysts need to know, and what could be coming next.

the Critical Exploit (CVE-2025-54309)

A newly discovered vulnerability in CrushFTP, now cataloged as CVE-2025-54309, is actively being exploited in the wild, putting critical infrastructure at severe risk. The flaw affects CrushFTP 10 versions before 10.8.5 and version 11 before 11.3.4_23—but only when the DMZ proxy feature is not in use. The flaw is rooted in how CrushFTP mishandles AS2 validation, which ultimately enables remote attackers to gain admin-level access over HTTPS.

The company admitted it first noticed live exploitation of this vulnerability on July 18, 2025, although malicious actors may have reverse-engineered the patch timeline and exploited the flaw earlier. Interestingly, CrushFTP had earlier released a fix for a related AS2 issue but didn’t realize a previously overlooked bug could still be weaponized. Hackers evidently analyzed the patch code and found a way to exploit the original flaw.

This is deeply troubling because CrushFTP is used to manage sensitive file transfers across mission-critical sectors such as healthcare, government, and finance. If an attacker gains admin access, they can exfiltrate sensitive data, deploy malware backdoors, and even pivot into internal trusted systems. Without DMZ isolation, compromised servers act as catastrophic single points of failure.

Some signs of compromise include:

Creation of long random admin user IDs

Modification of `user.xml` in the default user directory

Disappearance of interface buttons and sudden admin privileges for regular users

CrushFTP urges organizations to review system logs, especially the user.xml file, for irregularities. They also advise auditing IPs and admin access events. Among the recommended mitigations:

Restore previous user profiles from backups

Limit administrative IPs

Use IP allowlisting

Deploy a DMZ version of CrushFTP

Enable automatic updates

This is not the first time CrushFTP has faced such threats. Just this April, another flaw (CVE-2025-31161) was used to distribute malware like the MeshCentral agent, and CVE-2024-4040 was part of a coordinated attack on U.S. entities last year.

Clearly, CrushFTP is a high-value target for threat actors, and the latest exploit reinforces the urgency of proactive defense.

🔍 What Undercode Say:

Targeted Systemic Weakness

Undercode researchers highlight a deeper systemic issue beyond CVE-2025-54309 itself: a pattern of delayed response and insufficient patch segmentation. The fact that attackers could reverse-engineer a patch to find a prior bug underscores the risks of releasing updates without fully assessing the ripple effects of past vulnerabilities.

Exploitation Chain and Tactics

From an

No need for local access or social engineering

No need for DMZ feature to be disabled

Exploit via HTTPS (often overlooked in basic firewall setups)

Once admin access is achieved, typical behavior includes:

Modifying core user files like `MainUsers/default/user.xml`

Creating admin users with randomized identifiers

Escalating privileges on legitimate accounts

Covering tracks by altering UI elements (e.g., button disappearance)

Undercode notes these are classic post-exploitation signs, resembling tactics seen in state-sponsored campaigns.

Risk Amplification by Deployment Practices

CrushFTP is often deployed in environments with broad file access rights, minimal DMZ segmentation, and in some cases, exposed directly to the internet. This setup amplifies the blast radius of any breach. Lack of granular access controls or real-time monitoring can delay detection by weeks.

Recommendations from Undercode Analysts

Immediate upgrade to latest secure versions (10.8.5 or 11.3.4_23)

Enable DMZ proxy configurations for external file handling

Monitor `user.xml` modification timestamps and admin login IPs

Enable multi-factor authentication and enforce IP allowlisting

Implement file integrity monitoring (FIM) tools for sensitive directories

Consider deploying a zero-trust security model around CrushFTP usage

Undercode stresses that proactive patching and detailed change tracking are the only way to defend against CrushFTP’s growing attack surface. They also recommend automating alerts for any admin changes or unknown account creations.

✅ Fact Checker Results:

Confirmed: CVE-2025-54309 is rated 9.0 and actively exploited as of July 2025.
Verified: Flaw impacts CrushFTP versions prior to 10.8.5 / 11.3.4_23.
True: Admin access can be gained through HTTPS in absence of DMZ proxy configuration.

🔮 Prediction:

The CrushFTP platform is likely to face additional zero-day attacks in the coming months, as it has become a recurring target for advanced persistent threats (APTs). If organizations do not enforce strict segmentation and patch hygiene, future breaches could involve ransomware, credential harvesting, or supply chain compromises. Expect CVE-2025-54309 to be used in multi-stage attacks alongside other known vulnerabilities, especially in government and healthcare sectors.

References:

Reported By: thehackernews.com
Extra Source Hub:
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin