¡¾Îó²îͨ¸æ¡¿CrushFTP HTTP(S)Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-54309)

Ðû²¼Ê±¼ä 2025-08-28

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

CrushFTP HTTP(S)Ô¶³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2025-54309

Îó²îÀàÐÍ

RCE

·¢Ã÷ʱ¼ä

2025-08-28

Îó²îÆÀ·Ö

9.8

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

ÒÑ·¢Ã÷


CrushFTPÊÇÒ»¿î¿çƽ̨µÄ¸ßÐÔÄÜÎļþ´«Êä·þÎñÆ÷Èí¼þ £¬Ö§³Ö FTP¡¢FTPS¡¢SFTP¡¢HTTP¡¢HTTPS¡¢WebDAV¡¢SCP µÈ¶àÖÖЭÒé¡£ÆäÌØµãÊÇÒ×ÓÚ°²Åź͹ÜÀí £¬Ìṩ»ùÓÚ Web µÄ¹ÜÀí½çÃæºÍ¶à²ãÇå¾²¿ØÖÆ £¬°üÀ¨Óû§È¨ÏÞ¹ÜÀí¡¢SSL/TLS ¼ÓÃÜ¡¢IP »á¼û¿ØÖÆ¡¢Ë«ÒòËØÈÏÖ¤µÈ¡£CrushFTP ÆÕ±éÓ¦ÓÃÓÚÆóÒµ¼¶Çå¾²Îļþ¹²Ïí¡¢×Ô¶¯»¯Îļþ´«ÊäºÍÊý¾Ý¼¯³É³¡¾° £¬Ö§³Ö¼¯Èº¡¢¸ß¿ÉÓð²Åż° DMZ ¼Ü¹¹ £¬Êʺ϶ÔÊý¾ÝÇå¾²ºÍÐÔÄÜÒªÇó½Ï¸ßµÄÇéÐΡ£


2025Äê8ÔÂ28ÈÕ £¬×ðÁú¿­¹ÙÍøÈë¿Ú¼¯ÍÅVSRC¼à²âµ½CrushFTP±£´æHTTP(S)Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¸ÃÎó²îÓÚ2025Äê7ÔÂ18ÈÕÊ×´ÎÔÚÒ°Íâ±»·¢Ã÷ £¬ÏÖʵ¹¥»÷Ô˶¯¿ÉÄܸüÔç×îÏÈ¡£¹¥»÷Õßͨ¹ýÄæÏòÆÊÎöCrushFTPµÄ´úÂë¸üР£¬Ê¹ÓÃ7ÔÂ1ÈÕ֮ǰ°æ±¾ÖÐÒÑÐÞ¸´µÄHTTP(S)ȱÏÝ £¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£ÀÖ³ÉʹÓúó £¬¹¥»÷Õß¿Éͨ¹ýHTTP(S)ÇëÇó»ñÈ¡¹ÜÀíȨÏÞ²¢Ö²Èë¶ñÒâ¾ç±¾¡£ÈëÇÖ¼£Ïó°üÀ¨½¨ÉèÒì³£Ëæ»ú¹ÜÀíÔ±ÕË»§¡¢¸Ä¶¯°æ±¾ºÅÏÔʾÒÔ¼°Òþ²Ø½çÃæ°´Å¥µÈ¡£


¶þ¡¢Ó°Ïì¹æÄ£


CrushFTP 10.x < 10.8.5
CrushFTP 11.x < 11.3.4_23¡£


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼Çå¾²²¹¶¡ £¬Éý¼¶ÖÁÈçϰ汾¡£
½«CrushFTP 10.x Éý¼¶ÖÁ ¡Ý 10.8.5¡£
½«CrushFTP 11.x Éý¼¶ÖÁ ¡Ý 11.3.4_23¡£


3.2 ÔÝʱ²½·¥


ÆôÓÃIP°×Ãûµ¥£ºÉèÖÃCrushFTP½öÔÊÐíÌØ¶¨IPµØÖ·ÅþÁ¬·þÎñÆ÷ £¬½µµÍ±»É¨ÃèºÍʹÓõÄΣº¦¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬ïÔ̭ϵͳÎó²î £¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬Ð޸ķÀ»ðǽսÂÔ £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ £¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬ïÔÌ­¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
ÔöǿϵͳÓû§ºÍȨÏÞ¹ÜÀí £¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://www.crushftp.com/crush11wiki/Wiki.CompromiseJuly2025/
https://nvd.nist.gov/vuln/detail/CVE-2025-54309