CVE-2025-2825

EXPLOITED

(pending title)

Description

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-31161. Reason: This Record is a reservation duplicate of CVE-2025-31161. Notes: All CVE users should reference CVE-2025-31161 instead of this Record. All references and descriptions in this Record have been removed to prevent accidental usage.

Exploits (9)

nomisec WORKING POC 12 stars
by ghostsec420 · remote
https://github.com/ghostsec420/ShatteredFTP
nomisec WORKING POC 5 stars
by Shivshantp · remote
https://github.com/Shivshantp/CVE-2025-2825-CrushFTP-AuthBypass
nomisec WORKING POC 1 stars
by iteride · remote
https://github.com/iteride/CVE-2025-2825
nomisec WORKING POC 1 stars
by WOOOOONG · remote
https://github.com/WOOOOONG/CVE-2025-2825
gitlab WORKING POC
by Tekk0 · poc
https://gitlab.com/Tekk0/cve-2025-2825-crushftp-password-overwrite
nomisec WRITEUP
by punitdarji · infoleak
https://github.com/punitdarji/crushftp-CVE-2025-2825
vulncheck_xdb WORKING POC
remote
https://github.com/Immersive-Labs-Sec/CVE-2025-31161
vulncheck_xdb SCANNER
remote
https://github.com/SUPRAAA-1337/Nuclei_CVE-2025-31161_CVE-2025-2825
metasploit WORKING POC
by Outpost24, remmons-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/crushftp_authbypass_cve_2025_2825.rb

Scores

Exploitation Intel

VulnCheck KEV 2025-03-30

Classification

Status rejected

Timeline

Published Mar 26, 2025
Tracked Since Feb 18, 2026