CVE-2025-54309
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
5 articles
EPSS Score
Source: FIRST.org · 2026-05-24
76.8%
probability
This CVE has a 76.8% probability
of being exploited in the next 30 days.
0%
Top 99.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
watchtowrlabs/watchTowr-vs-CrushFTP-Authentication-Bypass-CVE-2025-54309
PoC CVE-2025-54309 — watchtowrlabs/watchTowr-vs-CrushFTP-Authentication-Bypass-CVE-2025-54309
28
foregenix/CVE-2025-54309
Exploitation scripts for the CrushFTP CVE-2025-54309: vulnerability
2
0xLittleSpidy/CVE-2025-54309
PoC CVE-2025-54309 — 0xLittleSpidy/CVE-2025-54309
1
chin-tech/CrushFTP_CVE-2025-54309
PoC CVE-2025-54309 — chin-tech/CrushFTP_CVE-2025-54309
0
fuckyourheroes/CVE-2025-54309
CrushFTP AS2 Authentication Bypass
0
whisperer1290/CVE-2025-54309__Enhanced_exploit
PoC CVE-2025-54309 — whisperer1290/CVE-2025-54309__Enhanced_exploit
0
6 repos — triés par ⭐
Rechercher sur GitHub ↗
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and More
TheHackerNews
Bruteforce Scans for CrushFTP , (Tue, Mar 3rd)
SANS-ISC
Mar 03, 2026
New CrushFTP zero-day exploited in attacks to hijack servers
BleepingComputer
Jul 18, 2025
Security Advisory 2025-028
CERT-EU
Jul 24, 2025
Signal Intelligence
Confidence
92%
EPSS
76.8%
Mentions
5
Last Seen
Mar 03, 2026
CNA Information
Analyst Note
CVE-2025-54309 is explicitly described in the official CVE description as 'exploited in the wild in July 2025,' matching the CVE publication date of 2025-07-18. Multiple authoritative sources (BleepingComputer, CERT-EU) explicitly label it as a 'zero-day exploited in attacks.' The critical CVSS 9.0 score and vendor patches (10.8.5, 11.3.4_23) confirm this is an active, unpatched vulnerability being exploited immediately upon discovery.
Threat Actors 4
Hacking Team
apt_group
🇮🇹 IT
Infy
apt_group
Information theft and espionage
🇮🇷 IR
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 05, 2026