CVE-2025-31161

CrushFTP Authentication Bypass Vulnerability

Description

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

Severity: CRITICAL

CVSS Score: 9.8

Vendor: CrushFTP

Product: CrushFTP

Loading CVE details...