CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation

Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.

security

Sources

Vulnerabilities

Why this score
Signals contributing to the severity score
SignalPoints
kev added50
kev ransomware10
epss high20
public poc — 20 repositories20
CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation · TechNews