CrushFTP Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for CrushFTP products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

4

In CISA KEV

3

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

CrushFTP KEVs Added by Year

Loading...

4 CrushFTP KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2023-43177

CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

High Not in CISA 28 Aug 2025
CVE-2025-54309

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote...

Confirmed In CISA 01 Jun 2026
CVE-2024-4040

Unauthenticated arbitrary file read and remote code execution in CrushFTP

Confirmed In CISA 24 Apr 2024
CVE-2025-31161

CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is...

Confirmed In CISA 07 Apr 2025

Common Vulnerability Classes (CWE)

  • CWE-1336 — Improper Neutralization of Special Elements Used in a Template Engine 1
  • CWE-305 — Authentication Bypass by Primary Weakness 1
  • CWE-420 — Unprotected Alternate Channel 1
  • CWE-913 — Improper Control of Dynamically-Managed Code Resources 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology