CrushFTP Security Update – 20 July 2025

CrushFTP has released a security update to fix a critical vulnerability in CrushFTP versions below “10.8.5 and 11.3.4_23”.

The addressed vulnerability could allow the attacker to gain elevated privileges and obtain administrative access to the affected system through HTTPS.

CrushFTP Privilege Escalation Vulnerability (CVE-2025-54309):

  • CVSS: 9.0
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privilege

It should be highlighted that CrushFTP is aware that the zero-day vulnerability “CVE-2025-54309” is being exploited in the wild.

Vulnerabilities

CVE-2025-54309

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

CrushFTP Security Update

References