CVE-2025-54309

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 5 articles

EPSS Score

Source: FIRST.org · 2026-05-24
76.8%
probability
This CVE has a 76.8% probability of being exploited in the next 30 days.
0% Top 99.0th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Attack Intelligence

Exploits & PoC

watchtowrlabs/watchTowr-vs-CrushFTP-Authentication-Bypass-CVE-2025-54309

PoC CVE-2025-54309 — watchtowrlabs/watchTowr-vs-CrushFTP-Authentication-Bypass-CVE-2025-54309

28
foregenix/CVE-2025-54309

Exploitation scripts for the CrushFTP CVE-2025-54309: vulnerability

2
0xLittleSpidy/CVE-2025-54309

PoC CVE-2025-54309 — 0xLittleSpidy/CVE-2025-54309

1
chin-tech/CrushFTP_CVE-2025-54309

PoC CVE-2025-54309 — chin-tech/CrushFTP_CVE-2025-54309

0
fuckyourheroes/CVE-2025-54309

CrushFTP AS2 Authentication Bypass

0
whisperer1290/CVE-2025-54309__Enhanced_exploit

PoC CVE-2025-54309 — whisperer1290/CVE-2025-54309__Enhanced_exploit

0
6 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 76.8%
Mentions 5
Last Seen Mar 03, 2026

CNA Information

Analyst Note

CVE-2025-54309 is explicitly described in the official CVE description as 'exploited in the wild in July 2025,' matching the CVE publication date of 2025-07-18. Multiple authoritative sources (BleepingComputer, CERT-EU) explicitly label it as a 'zero-day exploited in attacks.' The critical CVSS 9.0 score and vendor patches (10.8.5, 11.3.4_23) confirm this is an active, unpatched vulnerability being exploited immediately upon discovery.

Threat Actors 4

Hacking Team
apt_group 🇮🇹 IT
Infy
apt_group Information theft and espionage 🇮🇷 IR
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 05, 2026