As cited
Copy frozen at (site build).
vulnerabilities
CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation
Huntress detected active exploitation of CVE-2025-31161, an authentication bypass flaw in CrushFTP, followed by post-exploitation activity involving MeshCentral and additional malware. The vulnerability allows attackers to bypass authentication controls and establish persistence through secondary tools.
Why it matters: Organizations running vulnerable CrushFTP versions face immediate risk of unauthorized access and lateral movement; patching and monitoring for MeshCentral installation are critical next steps.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation
Huntress detected active exploitation of CVE-2025-31161, an authentication bypass flaw in CrushFTP, followed by post-exploitation activity involving MeshCentral and additional malware. The vulnerability allows attackers to bypass authentication controls and establish persistence through secondary tools.
Why it matters: Organizations running vulnerable CrushFTP versions face immediate risk of unauthorized access and lateral movement; patching and monitoring for MeshCentral installation are critical next steps.
- Source published
- First seen by Cybersecurity Tracker