CrushFTP has had authentication-bypass flaws that let an unauthenticated attacker reach administrative functions, and server-side template and path-handling issues that read arbitrary files or lead to code execution. As with other MFT products, the appliance is internet-facing and holds sensitive transfer data, so the bypass is immediately high-impact.
CrushFTP flaw classes:
- Unauthenticated access to admin/privileged functions
- Server-side template / path handling -> arbitrary file read or code execution
Exploitation notes#
- The bypass turns an unauthenticated request into administrative or privileged-user actions, exposing stored files and configuration.
- Template and path handling flaws escalate from file read to code execution on affected versions.
- Version fingerprinting from the login page and headers guides which technique applies.