{"cveID":"CVE-2025-54309","vendorProject":"CrushFTP","product":"CrushFTP","vulnerabilityName":" CrushFTP Unprotected Alternate Channel Vulnerability","dateAdded":"2025-07-22","shortDescription":"CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-08-12","knownRansomwareCampaignUse":"Unknown","notes":"https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54309 ","cwes":["CWE-420"],"year":2025,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2025-54309","technique":"T1068","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"exploitation_technique","capability_group":"auth_bypass","comments":"Improper validation of AS2 messages in CrushFTP without DMZ proxy enabled were reported to be exploited to bypass authentication and gain administrative access over HTTPS, leading to system compromise, data exfiltration, and lateral movement.","references":["https://zeropath.com/blog/crushftp-cve-2025-54309-as2-validation-flaw"," https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-54309","technique":"T1021","technique_name_at_mapping":"Remote Services","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"Improper validation of AS2 messages in CrushFTP without DMZ proxy enabled were reported to be exploited to bypass authentication and gain administrative access over HTTPS, leading to system compromise, data exfiltration, and lateral movement.","references":["https://zeropath.com/blog/crushftp-cve-2025-54309-as2-validation-flaw"," https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-54309","technique":"T1567","technique_name_at_mapping":"Exfiltration Over Web Service","mapping_type":"primary_impact","capability_group":"auth_bypass","comments":"Improper validation of AS2 messages in CrushFTP without DMZ proxy enabled were reported to be exploited to bypass authentication and gain administrative access over HTTPS, leading to system compromise, data exfiltration, and lateral movement.","references":["https://zeropath.com/blog/crushftp-cve-2025-54309-as2-validation-flaw"," https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1021","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Remote Services","name_at_mapping":"Remote Services","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":11,"has_detection_strategy":true},{"id":"T1068","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Privilege Escalation","name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":31,"has_detection_strategy":true},{"id":"T1567","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exfiltration Over Web Service","name_at_mapping":"Exfiltration Over Web Service","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":12,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":["0fdc7c7f-c690-4217-9ae3-31f5156eed72"],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}