
Kristian Varnai
Senior Security Consultant, Outpost24
Kristian is an experienced OffSec penetration tester and security researcher at Outpost24.
Application Security
02 Apr 2025
Outpost24 analysts recently discovered a critical authentication bypass vulnerability in CrushFTP, identified as CVE-2025-31161. The vulnerability has a CVSSv3.1 score of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8). We reached out to MITRE for a CVE on 13th March 2025 and were within an agreed…