Vendor
high
threat
CrushFTP Authentication Bypass Exploitation
1 rule 3 TTPs 1 CVECVE-2025-31161 in CrushFTP is being exploited to gain unauthorized access and execute malicious commands, with activity linked to Hellcat ransomware operations.
exploited
CrushFTP
web
ransomware
vulnerability
1r
3t
1c
critical
threat
CrushFTP Server-Side Template Injection Exploitation
2 rules 2 TTPs 1 CVEExploitation of CVE-2024-4040, a server-side template injection vulnerability in CrushFTP, allows unauthenticated remote attackers to access files, circumvent authentication, and execute arbitrary commands.
exploited
CrushFTP Server
crushftp
ssti
cve-2024-4040
2r
2t
1c