> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CVE-2025-2825: Unauthenticated HTTP(S) port access on CrushFTPv10/v11
- URL: https://darkwebinformer.com/cve-2025-2825-unauthenticated-http-s-port-access-on-crushftpv10-v11/
- Published: 2025-03-26T18:05:14.000Z
- Updated: 2025-09-04T22:23:13.000Z
- Author: Dark Web Informer
- Tags: Vulnerabilities

🚨 Critical Security Vulnerability  
🆔 CVE-2025-2825  
💣 CVSS Score: 9.8  
📅 Published Date: 2025-03-26

⚠️ CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability that may result in unauthenticated access. Remote and unauthenticated HTTP requests to CrushFTP may allow attackers to gain unauthorized access.

🛠 References:  
🔗 CrushFTP: <https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update>  
🔗 NIST: <https://nvd.nist.gov/vuln/detail/CVE-2025-2825>