# CVE-2025-32103

## Summary

- **CVE ID:** CVE-2025-32103
- **Severity:** MEDIUM
- **CVSS Score:** 5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N)
- **CWE:** CWE-40
- **Published:** Apr 15, 2025
- **Last Modified:** Mar 13, 2026

## Description

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.

## Affected Products

- CrushFTP — CrushFTP (9)
- CrushFTP — CrushFTP (11)

## References

- [CNA](https://www.crushftp.com/)
- [CNA](https://seclists.org/fulldisclosure/2025/Apr/17)
- [CNA](https://packetstorm.news/files/id/190460/)
- [CVE](http://seclists.org/fulldisclosure/2025/Apr/17)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 16.73%
- **EPSS Percentile:** 96.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._