CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation
Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.
Sources
Vulnerabilities
Why this score
| Signal | Points |
|---|---|
| kev added | 50 |
| kev ransomware | 10 |
| epss high | 20 |
| public poc — 20 repositories | 20 |