Description |
FortiGuard Labs have observed exploitation attempts of CVE-2025-31161 in CrushFTP Server.
CrushFTP Server is a file transfer server that supports multiple protocols and multiple platforms.
CVE-2025-31161 is an authentication bypass vulnerability in CrushFTP server which a specialty crafted HTTP request would allow complete control over the CrushFTP server.
The following versions of CrushFTP server are vulnerable to CVE-2025-31161:
|
||||||
CVE ID |
CVE-2025-31161 (https://nvd.nist.gov/vuln/detail/CVE-2025-31161) |
||||||
NDR Cloud Detection Rule |
FortiNDR Cloud v25.2b+
|
||||||
Playbook | N/A | ||||||
Threat Hunting |
FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for “CrushFTP Authentication Bypass Attack” related activities: All IOCs listed above have been added to Threat Intelligence Intel. |
||||||
Suricata Coverage |
Customers can create custom investigation/detections using the Suricata signatures below: 2061619 -> ET EXPLOIT [CORELIGHT] CrushFTP Auth Bypass Attempt (CVE-2025-31161) |
||||||
Other Fortinet Products |
For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.