New assessment for topic: CVE-2025-54309
Topic description: "CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025. ..."
"On Friday, July 18, 2025, managed file transfer vendor CrushFTP released information to a private mailing list on a [new critical vulnerability](https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025), tracked as [CVE-2025-54309](https://nvd.nist.gov/vuln/detail/CVE-2025-54309), affecting versions below 10.8.5 and 11.3.4_23 across all platforms ..."
Link:
https://attackerkb.com/assessments/d47ba11a-b2cc-4f24-97ba-2ec8f7dc4915