Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
CrushFTP, LLC

CrushFTP, LLC Vendor Cyber Rating & Cyber Score

crushftp.com

Put simply, CrushFTP is a secure high speed file transfer server that runs on almost any OS. It handles a wide array of protocols, and security options. It gives the server administrator the ability to customize, monitor, and control every aspect of the server’s operations. CrushFTP is stand alone and self contained. It doesn’t run on top of another vendors’ server code, or rely on another vendors application container. The HTTP server isn’t based on Tomcat, or others. This means that when vulnerabilities are discovered for Tomcat, you don’t have to go run and patch your server to keep it secure. CrushFTP maintains its own security stack, which is comprised of industry standard, enterprise-grade technologies. This also means that the


CrushFTP, LLC A.I CyberSecurity Scoring

CrushFTP, LLC
Company Information
Website:https://www.crushftp.com/
Employees number:3
Number of followers:81
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:crushftp.com
CrushFTP, LLC Risk Score (AI oriented)
Between 700 and 749
logo
CrushFTP, LLCIT Services and IT Consulting
Updated:
04/04/2026
747/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CrushFTP, LLC Global Score (TPRM)
xxxx
logo
CrushFTP, LLCIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CrushFTP, LLC
CrushFTP, LLCModerate
Current Score
747Ba (MODERATE)
01000
2 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
747Before Incident
MAY 2026
747Before Incident
APRIL 2026
747Before Incident
MARCH 2026
747Before Incident
FEBRUARY 2026
746Before Incident
JANUARY 2026
746Before Incident
DECEMBER 2025
745Before Incident
NOVEMBER 2025
745Before Incident
OCTOBER 2025
745Before Incident
SEPTEMBER 2025
745Before Incident
AUGUST 2025
744Before Incident
JULY 2025
744Before Incident
JUNE 2025
749Before Incident
Vulnerability
16 Jun 2025CrushFTP, LLC
CrushFTP

Zero-Day Vulnerability in CrushFTP (CVE-2025-54309)

743After Incident
CRITICAL-6
CRU243073125
A significant zero-day vulnerability in CrushFTP has been disclosed, allowing unauthenticated attackers to achieve complete remote code execution on vulnerable servers. The flaw, tracked as CVE-2025-54309 and scoring a critical 9.8 on the CVSS scale, stems from a fundamental breakdown in security checks within CrushFTP’s DMZ proxy configuration. Security researchers have already released proof-of-concept exploit code, significantly raising the urgency for organizations running CrushFTP to implement immediate protective measures.
INCIDENT DETAILS -
TYPE
Zero-Day Vulnerability
MOTIVATION
Remote Code Execution (RCE)
IMPACT
CrushFTP servers with DMZ proxy configuration
MAY 2025
750Before Incident
Vulnerability
01 May 2025CrushFTP, LLC
CrushFTP

CrushFTP Zero-Day Vulnerability Exploitation (CVE-2025-54309)

748After Incident
LOW-2
CRU709072025
CrushFTP is warning about a zero-day vulnerability (CVE-2025-54309) that allows attackers to gain administrative access via the web interface on vulnerable servers. The vulnerability was first detected on July 18th, but it may have been exploited earlier. A prior fix inadvertently blocked this vulnerability, but threat actors reverse-engineered the software and began exploiting it on unpatched systems. Systems kept up to date are not vulnerable. Indicators of compromise include unexpected entries in user.XML and new, unrecognized admin-level usernames. It is unclear if the attacks were used for data theft or to deploy malware, but similar platforms have been targeted by ransomware gangs for mass data theft and extortion attacks.
INCIDENT DETAILS -
TYPE
Zero-Day Exploitation
IMPACT
CrushFTP servers prior to v10.8.5 and v11.3.4_23

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CrushFTP, LLC ?
?
What was CrushFTP, LLC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CrushFTP, LLC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CrushFTP, LLC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CrushFTP, LLC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CrushFTP, LLC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CrushFTP, LLC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CrushFTP, LLC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CrushFTP, LLC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was CrushFTP, LLC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was CrushFTP, LLC's A.I Rankiteo Cyber Score in August 2025 ?
?
What was CrushFTP, LLC's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on CrushFTP, LLC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CrushFTP, LLC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CrushFTP, LLC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
CrushFTP, LLC Cyber Scoring History | Rankiteo