{"id":5776,"date":"2025-07-31T10:04:58","date_gmt":"2025-07-31T10:04:58","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/31\/critical-crushftp-0-day-rce-vulnerability-technical-details-and-poc-released\/"},"modified":"2025-07-31T10:04:58","modified_gmt":"2025-07-31T10:04:58","slug":"critical-crushftp-0-day-rce-vulnerability-technical-details-and-poc-released","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/31\/critical-crushftp-0-day-rce-vulnerability-technical-details-and-poc-released\/","title":{"rendered":"Critical CrushFTP 0-Day RCE Vulnerability Technical Details and PoC Released"},"content":{"rendered":"<p>    Critical CrushFTP 0-Day RCE Vulnerability Technical Details and PoC Released<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A significant zero-day vulnerability in CrushFTP has been disclosed, allowing unauthenticated attackers to achieve complete remote code execution on vulnerable servers.\u00a0<\/p>\n<p>The flaw, tracked as <a href=\"https:\/\/cybersecuritynews.com\/crushftp-0-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-54309<\/a> and scoring a critical 9.8 on the CVSS scale, stems from a fundamental breakdown in security checks within CrushFTP\u2019s DMZ proxy configuration.\u00a0<\/p>\n<p>Security researchers have already released proof-of-concept exploit code, significantly raising the urgency for organizations running CrushFTP to implement immediate protective measures.<\/p>\n<pre class=\"wp-block-preformatted\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Key Takeaways<\/mark><\/strong><br>1. CVE-2025-54309 allows unauthenticated remote code execution on CrushFTP servers.<br>2. Exploits use malicious XML payloads to bypass authentication and execute system commands.<br>3. Public exploit code available - immediate patching required.<\/pre>\n<h2 class=\"wp-block-heading\"><strong>Technical Details of the Vulnerability<\/strong><\/h2>\n<p>According to pwn.guide <a href=\"https:\/\/pwn.guide\/free\/web\/crushftp\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">advisory<\/a>, the core vulnerability lies in CrushFTP\u2019s failure to properly authenticate requests to the \/WebInterface\/function\/ admin endpoint.\u00a0<\/p>\n<p>In normal operations, the DMZ proxy should act as a secure gateway protecting internal admin servers from public internet access.<\/p>\n<p>However, this security mechanism completely fails when processing specially crafted HTTP POST requests, allowing attackers to bypass authentication entirely.<\/p>\n<p>The primary exploitation method leverages the XML-RPC (XML Remote Procedure Call) protocol to execute arbitrary system commands.\u00a0<\/p>\n<p>Attackers can send malicious XML payloads containing the system.exec function call to execute operating system commands directly. A typical attack payload appears as:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfidOQ3BTVmV955OjagkPUBgXTg7RQIao-qdn-XCbvWahy041abmT1k0EcsHNFGe6sw-_rwUUntog3F6NX6wEZMduJJT2PTeCUQ-Tega6IsvCd1fbWyqA04fIcssGN9tAQnSrMCwQ?key=KOtt4HOYrR0qrZpMIpwKLQ\" alt=\"\"><\/figure>\n<\/div>\n<p>This vulnerability achieves its critical CVSS 9.8 rating due to three key factors: no <a href=\"https:\/\/cybersecuritynews.com\/authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication<\/a> requirements, remote accessibility from anywhere on the internet, and complete system compromise through RCE capabilities.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Risk Factors<\/strong><\/td>\n<td><strong>Details<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Affected Products<\/td>\n<td>CrushFTP servers with DMZ proxy configuration<\/td>\n<\/tr>\n<tr>\n<td>Impact<\/td>\n<td>Remote Code Execution (RCE)<\/td>\n<\/tr>\n<tr>\n<td>Exploit Prerequisites<\/td>\n<td>\u2013 No authentication required- Network access to \/WebInterface\/function\/ endpoint- HTTP POST capability- XML-RPC payload crafting<\/td>\n<\/tr>\n<tr>\n<td>CVSS 3.1 Score<\/td>\n<td>9.8 (Critical)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>Proof-of-Concept Exploitation\u00a0<\/strong><\/h2>\n<p>Security researchers have published a comprehensive PoC script on GitHub. The exploit tool supports multiple attack vectors, including direct XML-RPC command execution, command injection through login forms, and malicious file uploads.<\/p>\n<p>The basic exploitation command structure follows: python3 exploit.py 192.168.1.100 -c \u201cuname -a\u201d, where the script generates XML-RPC payloads and delivers them to the vulnerable \/WebInterface\/function\/ endpoint.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXf6NlV_GlSsYtFH3U_v-XV9Qr4NPTFIMfUqDUDny79n0eMq77JyDNrZtz0PIkfs0mrnhizk04fPbmCSKCr4dhDMszHYfVKrgVtwx2RHb6VzKgpRTXK2zj9yc-LZ5fI94d_FqvyM?key=KOtt4HOYrR0qrZpMIpwKLQ\" alt=\"\"><\/figure>\n<\/div>\n<p>Advanced attack modes include reconnaissance scanning with \u2013recon flags and alternative payload types like cmd_inject for command injection attacks.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXc0OkNhD435y8fAhk3VtUm18AE2AA_uKc0E3VG2JH08TiEVylUmjVIJgEXyamTEa-IUWoZcEl23bVxyDsg13CKgYLYKC2O0UMOCWQFpYPFi22cT1ybVUHTHanRId5fAXqyXVwJ4YA?key=KOtt4HOYrR0qrZpMIpwKLQ\" alt=\"\"><\/figure>\n<\/div>\n<p>Organizations running CrushFTP should immediately implement network-level restrictions to block unauthorized access to admin endpoints, apply any available vendor patches, and monitor for suspicious XML-RPC requests targeting the \/WebInterface\/function\/ path.\u00a0<\/p>\n<p>The combination of public PoC availability and the vulnerability\u2019s severe impact makes this a prime target for widespread exploitation campaigns.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 95%,rgb(169,184,195) 100%)\"><code><strong>Integrate <strong>ANY.RUN TI Lookup<\/strong> with your SIEM or SOAR To Analyses Advanced Threats<\/strong> -&gt; <strong><a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jul&amp;utm_medium=atricle&amp;utm_campaign=want-to-detect-incidents-before&amp;utm_content=plans1&amp;utm_term=290725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try 50 Free Trial Searches<\/a> <\/strong><\/code><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/crushftp-0-day-technical-details-poc-released\/\">Critical CrushFTP 0-Day RCE Vulnerability Technical Details and PoC Released<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/crushftp-0-day-technical-details-poc-released\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical CrushFTP 0-Day RCE Vulnerability Technical Details and PoC Released A significant zero-day vulnerability in CrushFTP has been disclosed, allowing unauthenticated attackers to achieve complete remote code execution on vulnerable servers.\u00a0 The flaw, tracked as CVE-2025-54309 and scoring a critical 9.8 on the CVSS scale, stems from a fundamental breakdown in security checks within CrushFTP\u2019s [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-5776","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5776"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5776"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5776\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5776"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5776"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5776"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}