CVE-2025-32103
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
- EPSS probability
- 16.73%
- CWE
- CWE-40
- Published
- 2025-04-15
- Last modified
- 2026-03-13
Affected products
- CrushFTP CrushFTP
- CrushFTP CrushFTP
Weakness type
Related vulnerabilities
- CVE-2026-25039 — The application evaluate UNC path in workspace name
- CVE-2026-27615 — ADB-Explorer: UNC Path Support in ManualAdbPath Leads to Remote Code Execution (RCE)
- CVE-2023-29446 — Improper Input Validation in PTC's Kepware KEPServerEX
- CVE-2021-44548 — Apache Solr information disclosure vulnerability through DataImportHandler