
Exploit script for CrushFTP authentication bypass (CVE-2025-2825) using crafted Authorization header and CrushAuth cookie to gain unauthorized access.
This script exploits the CrushFTP authentication bypass vulnerability in versions:
CrushFTP's AWS S3-style authentication can be bypassed using:
Authorization headerCrushAuth cookie where the last 4 chars match c2f paramchmod +x exploit_crushftp.sh
./exploit_crushftp.sh http://<target>:<port>