# CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation

DevFeed: [CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation](<https://devfeed.tech/articles/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation-54264.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation>)

Author: Huntress Adversary Tactics

Published: 2025-04-04T05:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [NVD](<https://devfeed.tech/topics/nvd.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [authentication-bypass](<https://devfeed.tech/tags/authentication-bypass.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cvss](<https://devfeed.tech/tags/cvss.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [http](<https://devfeed.tech/tags/http.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [in-the-wild-exploitation](<https://devfeed.tech/tags/in-the-wild-exploitation.md>), [malware](<https://devfeed.tech/tags/malware.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [patching](<https://devfeed.tech/tags/patching.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Huntress reports in-the-wild exploitation of the critical CrushFTP CVE-2025-31161 authentication-bypass vulnerability. The writeup describes affected versions, a proof of concept, and post-exploitation activity involving MeshCentral and other malware.

## Source excerpt

Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.