CVE-2024-4040: critical vulnerability in CrushFTP
Unauthenticated arbitrary file read and remote code execution in CrushFTP
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CrushFTP has a critical flaw that lets attackers without any login credentials read files from the server, take over as administrator, and run harmful code—all remotely and without authentication.
A server-side template injection vulnerability in CrushFTP versions before 10.7.1 and 11.1.0 allows unauthenticated remote attackers to execute arbitrary code and bypass authentication mechanisms. The vulnerability enables unauthorized file system access outside the VFS sandbox and elevation to administrative privileges, affecting all platforms.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.