
CVE-2025-31161
An unauthenticated remote attacker can impersonate any known user (including the default crushadmin administrator account) by exploiting a flaw in the AWS4-HMAC-SHA256 authorization header processing.
This vulnerability has been actively exploited in the wild and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog.
| Attribute | Details |
|---|---|
| CVE ID | CVE-2025-31161 |
| Severity | Critical (CVSS 9.8) |
| Affected Versions | CrushFTP 10.0.0 – 10.8.3 CrushFTP 11.0.0 – 11.3.0 |
| Patched Versions | CrushFTP 10.8.4 and 11.3.1 |
| Vulnerability Type | Authentication Bypass |
| Attack Vector | HTTP/HTTPS (S3-compatible authorization header) |
| Authentication | None Required |
| Impact | Full admin takeover, file access, data exfiltration, and potential server compromise |
The vulnerability stems from a race condition and improper parsing in the AWS4-HMAC authorization mechanism. By sending a specially crafted header with a known username (e.g., crushadmin/), attackers can bypass authentication and impersonate any user.
This repository is provided for educational and security research purposes only.
The information is intended to help organizations understand the severity of this vulnerability and apply timely mitigation.
Unauthorized exploitation against systems you do not own is illegal and unethical.
Made for Security Awareness & Responsible Research
⭐ If this helped you, please star the repository!