CrushFTP是CrushFTP公司的一款文件传输服务器。 CrushFTP 10.8.5之前版本和11.3.4_23之前版本存在安全漏洞,该漏洞源于AS2验证处理不当,可能导致远程攻击者获取管理员权限。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | CrushFTP Unauthenticated Remote Command Execution Exploit | https://github.com/issamjr/CVE-2025-54309-EXPLOIT | POC详情 |
| 2 | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025. | https://github.com/projectdiscovery/nuclei-templates/blob/main/code/cves/2025/CVE-2025-54309.yaml | POC详情 |
| 3 | None | https://github.com/watchtowrlabs/watchTowr-vs-CrushFTP-Authentication-Bypass-CVE-2025-54309 | POC详情 |
| 4 | CrushFTP AS2 Authentication Bypass | https://github.com/blueisbeautiful/CVE-2025-54309 | POC详情 |
| 5 | None | https://github.com/whisperer1290/CVE-2025-54309__Enhanced_exploit | POC详情 |
| 6 | None | https://github.com/chin-tech/CrushFTP_CVE-2025-54309 | POC详情 |
| 7 | CrushFTP AS2 Authentication Bypass | https://github.com/brokendreamsclub/CVE-2025-54309 | POC详情 |
| 8 | Exploitation scripts for the CrushFTP CVE-2025-54309: vulnerability | https://github.com/foregenix/CVE-2025-54309 | POC详情 |
| 9 | Findings & july race with 0day in wild | https://github.com/Smileyface101/CrushFTP-AS2-Bypass-Research-CVE-2025-54309 | POC详情 |
| 10 | None | https://github.com/0xLittleSpidy/CVE-2025-54309 | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论