Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers
July 20, 2025
1 min read
●
The Hacker News

A newly disclosed critical security flaw in CrushFTP has come under active exploitation in the wild. Assigned the CVE identifier CVE-2025-54309, the vulnerability carries a CVSS score of 9.0. "CrushFTP 10 before 10.8.5 and