CrushFTP Urges Immediate Patching of Unauthenticated Access Vulnerability
Source: bleepingcomputer.com Critical Security Flaw Discovered CrushFTP has issued an urgent security warning to its users, advising them to patch their servers immediately due to a newly discovered vulnerability that allows unauthenticated access to servers exposed on the internet via HTTP(S). The company disclosed the issue in an email to customers on March 21, 2025, stressing the importance of immediate action. According to the company, all versions of CrushFTP v11 are affected by this security flaw, though earlier versions remain unaffected. A CVE identifier for the vulnerability is expected to be assigned soon. The vulnerability presents a significant risk, as attackers could exploit exposed HTTP(S) ports to gain unauthorized access. However, servers with the DMZ (demilitarized zone) feature enabled are not affected. While CrushFTP initially stated that only v11 was impacted, a security advisory released on the same day suggests that both versions 10 and 11 are at risk, a findin...