CrushFTP Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for CrushFTP products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
4
In CISA KEV
3
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
CrushFTP KEVs Added by Year
4 CrushFTP KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2023-43177
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes. |
CrushFTP | High | Not in CISA | 28 Aug 2025 |
|
CVE-2025-54309
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote... |
CrushFTP | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2024-4040
Unauthenticated arbitrary file read and remote code execution in CrushFTP |
CrushFTP | Confirmed | In CISA | 24 Apr 2024 |
|
CVE-2025-31161
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is... |
CrushFTP | Confirmed | In CISA | 07 Apr 2025 |
Common Vulnerability Classes (CWE)
- CWE-1336 — Improper Neutralization of Special Elements Used in a Template Engine 1
- CWE-305 — Authentication Bypass by Primary Weakness 1
- CWE-420 — Unprotected Alternate Channel 1
- CWE-913 — Improper Control of Dynamically-Managed Code Resources 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology