A critical vulnerability in CrushFTP, a widely used enterprise file transfer solution, has been actively exploited in the wild following the release of a proof-of-concept exploit. The vulnerability, identified as CVE-2025-31161, allows unauthenticated attackers to achieve remote code execution, upload and download files, and create backdoor accounts on vulnerable systems.
The severity of this vulnerability is underscored by its CVSS base score of 9.8, reflecting the ease of exploitation and the potential for complete system compromise. With tens of thousands of CrushFTP instances publicly accessible online, the potential impact of this vulnerability is significant.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-31161 to its Known Exploited Vulnerabilities (KEV) catalog, indicating that the vulnerability is a frequent target for malicious actors.
Organizations using CrushFTP are strongly advised to update to the latest version immediately to mitigate this threat. Additionally, it is recommended to review system logs for any signs of compromise and to implement network segmentation and other security best practices to limit the potential impact of a successful exploit.
This incident serves as a stark reminder of the importance of timely patching and proactive vulnerability management, particularly for internet-facing systems. The rapid weaponization of this vulnerability highlights the need for a robust and agile security posture in the face of an ever-evolving threat landscape.