<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — CrushFTP</title><description>Actively exploited vulnerabilities affecting CrushFTP products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/crushftp.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-54309 —  CrushFTP Unprotected Alternate Channel Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-54309</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-54309</guid><description>CrushFTP&apos;s DMZ proxy feature, when not in use, fails to properly validate AS2 protocol requests over HTTPS. This allows unauthenticated remote attackers to gain full administrator access to the CrushFTP server without any credentials. Admin-level access means an attacker can read, modify, or exfiltrate any data managed by the file transfer server, making this a critical exposure for organizations using CrushFTP for business file exchange.</description><pubDate>Tue, 22 Jul 2025 00:00:00 GMT</pubDate><category>CrushFTP</category><category>CrushFTP</category></item></channel></rss>