CVE-2025-54309: CrushFTP – Authentication Bypass Race Condition

CVE-2025-54309: CrushFTP - Authentication Bypass Race Condition-渗透云记 - 专注于网络安全与技术分享
CVE-2025-54309: CrushFTP – Authentication Bypass Race Condition
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-54309: CrushFTP – Authentication Bypass Race Condition

漏洞描述

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享