¡¾Îó²îͨ¸æ¡¿CrushFTP HTTP(S)Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-54309)

Ðû²¼Ê±¼ä 2025-08-28

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

CrushFTP HTTP(S)Ô¶³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2025-54309

Îó²îÀàÐÍ

RCE

·¢Ã÷ʱ¼ä

2025-08-28

Îó²îÆÀ·Ö

9.8

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

ÒÑ·¢Ã÷


CrushFTPÊÇÒ»¿î¿çƽ̨µÄ¸ßÐÔÄÜÎļþ´«ÊäЧÀÍÆ÷Èí¼þ£¬£¬£¬£¬£¬£¬Ö§³Ö FTP¡¢FTPS¡¢SFTP¡¢HTTP¡¢HTTPS¡¢WebDAV¡¢SCP µÈ¶àÖÖЭÒé¡£¡£ÆäÌØµãÊÇÒ×ÓÚ°²ÅźÍÖÎÀí£¬£¬£¬£¬£¬£¬Ìṩ»ùÓÚ Web µÄÖÎÀí½çÃæºÍ¶à²ãÇå¾²¿ØÖÆ£¬£¬£¬£¬£¬£¬°üÀ¨Óû§È¨ÏÞÖÎÀí¡¢SSL/TLS ¼ÓÃÜ¡¢IP »á¼û¿ØÖÆ¡¢Ë«ÒòËØÈÏÖ¤µÈ¡£¡£CrushFTP ÆÕ±éÓ¦ÓÃÓÚÆóÒµ¼¶Çå¾²Îļþ¹²Ïí¡¢×Ô¶¯»¯Îļþ´«ÊäºÍÊý¾Ý¼¯³É³¡¾°£¬£¬£¬£¬£¬£¬Ö§³Ö¼¯Èº¡¢¸ß¿ÉÓð²Åż° DMZ ¼Ü¹¹£¬£¬£¬£¬£¬£¬Êʺ϶ÔÊý¾ÝÇå¾²ºÍÐÔÄÜÒªÇó½Ï¸ßµÄÇéÐΡ£¡£


2025Äê8ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½CrushFTP±£´æHTTP(S)Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¸ÃÎó²îÓÚ2025Äê7ÔÂ18ÈÕÊ×´ÎÔÚÒ°Íâ±»·¢Ã÷£¬£¬£¬£¬£¬£¬ÏÖʵ¹¥»÷»î¶¯¿ÉÄܸüÔç×îÏÈ¡£¡£¹¥»÷Õßͨ¹ýÄæÏòÆÊÎöCrushFTPµÄ´úÂë¸üУ¬£¬£¬£¬£¬£¬Ê¹ÓÃ7ÔÂ1ÈÕ֮ǰ°æ±¾ÖÐÒÑÐÞ¸´µÄHTTP(S)ȱÏÝ£¬£¬£¬£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£ÀÖ³ÉʹÓú󣬣¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýHTTP(S)ÇëÇó»ñÈ¡ÖÎÀíȨÏÞ²¢Ö²Èë¶ñÒâ¾ç±¾¡£¡£ÈëÇÖ¼£Ïó°üÀ¨½¨ÉèÒì³£Ëæ»úÖÎÀíÔ±ÕË»§¡¢¸Ä¶¯°æ±¾ºÅÏÔʾÒÔ¼°Òþ²Ø½çÃæ°´Å¥µÈ¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


CrushFTP 10.x < 10.8.5
CrushFTP 11.x < 11.3.4_23¡£¡£


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼Çå¾²²¹¶¡£¬£¬£¬£¬£¬£¬Éý¼¶ÖÁÈçϰ汾¡£¡£
½«CrushFTP 10.x Éý¼¶ÖÁ ¡Ý 10.8.5¡£¡£
½«CrushFTP 11.x Éý¼¶ÖÁ ¡Ý 11.3.4_23¡£¡£


3.2 ÔÝʱ²½·¥


ÆôÓÃIP°×Ãûµ¥£ºÉèÖÃCrushFTP½öÔÊÐíÌØ¶¨IPµØµãÅþÁ¬Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬½µµÍ±»É¨ÃèºÍʹÓõÄΣº¦¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£


3.4 ²Î¿¼Á´½Ó


https://www.crushftp.com/crush11wiki/Wiki.CompromiseJuly2025/
https://nvd.nist.gov/vuln/detail/CVE-2025-54309