CVE-2025-54309: CrushFTP Unprotected Alternate Channel Vulnerability.

CrushFTP Unprotected Alternate Channel Vulnerability. CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.

Detection rules

Browse the CVE database

Read the full analysis on IntelFusions