CVE-2025-54309: presente nel catalogo CISA KEV

CVE-2025-54309 · CVSS 9.0 CRITICAL · EPSS 94% · KEV 2025-07-22

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.

CVE-2025-54309 viene sfruttato?

Quali prodotti e versioni sono interessati?

Nessun elenco di pacchetti interessati registrato qui.

Esiste una patch?

Nessun identificativo di patch registrato qui.

Cosa ha pubblicato PlainSec su CVE-2025-54309

Fonti primarie

Cosa questa scheda non dice

KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-08-11.