Possible CrushFTP CVE-2025-31161 Authentication Bypass via Webserver

PremiumReviewedSigma · High · v1
Category
webserver
Author
HuntRule
Published
2026-10-01
Updated
2026-10-01

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects exploitation attempts against CrushFTP CVE-2025-31161 where a request to the getUserList API function carries a forged AWS4-HMAC-SHA256 authorization referencing the crushadmin account. Huntress observed this auth-bypass request used to impersonate the built-in administrator and enumerate accounts. Successful exploitation gives an unauthenticated attacker administrative control of the file transfer server enabling data theft and follow-on intrusion.

Related detections9 linkedT1190 — drag to rearrange
Suspicious SmarterMail Force Password Reset API Request Indicating Account Takeover
Suspicious SolarWinds Web Help Desk Java Process Spawning Command Shell
Malicious IIS Worker Process Spawning PowerShell via Gladinet CentreStack Exploit
Suspicious PowerShell Out-of-Band Request to Interactsh Domain
Exchange Worker Process Spawning Command Shell via OWASSRF
Suspicious PowerShell Spawned by SysAid Java Process
Suspicious Shell or Installer Spawned by ActiveMQ Java Process
Suspicious Cleo Autorun Healthcheck File Creation
ScreenConnect Administrator Provisioning XML Written to Temp Directory (CWE-288)
Possible CrushFTP CVE-2025-31161 Authentication Bypass via Webserver
Pivot detection · T1190 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.