CVE-2025-31161
- CVSS
- —
- EPSS
- 1.000 (100.0th percentile)
- CISA KEV
- Added 2025-04-07, due 2025-04-28
- Exploitation
- No report
- Public exploits
- 20 repositories
- State
- Unknown
Coverage
Actively exploitedCritical 100Huntress
CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation
Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev