Identity & Access · Credential Theft

CrushFTP Admin Accounts Targeted by Brute-Force Scans

Attempts are attributed to 5.189.139.225, seen probing since February.

1 source · Mar 3

CVE-2025-31161

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: crushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Apr 28 · date passed

CVE-2024-4040

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms… EPSS 100% (100th percentile).

CISA federal remediation date May 1 · date passed

CVE-2025-54309

NVD KEV

Known exploited · CISA KEV

CVSS 9 CRITICAL: crushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation… EPSS 95% (100th percentile).

CISA federal remediation date Aug 12 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-03-04

Every edition of this story: CrushFTP Admin Accounts Targeted by Brute-Force Scans