---
title: [🤓Geek Alert!🚨] How SMEs around the world are affected by disclosed vulnerabilities?
description: SMEs worldwide are affected by disclosed vulnerabilities in the FTP, FTPS, SFTP, HTTP, HTTPS, and WebDAV protocols. The CrushFTP and 🚨CVE-2025-2825 🚨
image: https://www.blackbullet.ro/hubfs/AI-Generated%20Media/Images/The%20image%20depicts%20a%20digital%20landscape%20filled%20with%20abstract%20representations%20of%20cybersecurity%20threats%20Central%20to%20the%20composition%20is%20a%20stylized%20large%20padlock%20symbolizing%20security%20which%20is%20cracked%20and%20partially%20open%20suggesting%20vulnerability%20Surrounding%20t-1.jpeg
---

[![BlackBullet-Logo](https://www.blackbullet.ro/hubfs/BlackBullet_-2.png)](https://www.blackbullet.ro/)

- [Cyber Security Services](https://www.blackbullet.ro/cyber-security)
  
  ### [Vulnerability Assessments  ](https://www.blackbullet.ro/cyber-security/vulnerability-assessments)
  
  
  
  ### [Penetration Testing Services  ](https://www.blackbullet.ro/cyber-security/penetration-testing)
  
  
  
  ### [Security Assessment  ](https://www.blackbullet.ro/cyber-security/security-assessment)
  
  
  
  ### [Awareness and Training  ](https://www.blackbullet.ro/cyber-security/awarness-and-training-programs)
  
  
  
  ### [Security Incident Response  ](https://www.blackbullet.ro/cyber-security/security-incident-response)
  
  
  
  ### [PKI - Public Key Infrastructure  ](https://www.blackbullet.ro/cyber-security/pki-public-key-insfrastructure)
  
  
  
  ### [Malware Analysis & Removal  ](https://www.blackbullet.ro/cyber-security/malware-analysis-and-removal)
  
  
  
  ### [Governance, Risk Analysis And Compliance  ](https://www.blackbullet.ro/cyber-security/grc-governance-risk-compliance)
- [Compliance Services](https://www.blackbullet.ro/en/nis-2-consultancy-and-implementation-services)
  
  [Compliance assessments,  in‑depth gap assessments, tailored strategies, implementation, and ongoing support to protect data and build customer trust](https://www.blackbullet.ro/en/nis-2-consultancy-and-implementation-services)
  
  ### [NIS 2 Compliance Gain a Clear Understanding of NIS 2 Legal Frameworks](https://www.blackbullet.ro/en/nis-2-consultancy-and-implementation-services)
- [About us](https://www.blackbullet.ro/about/)
- [Blog](https://www.blackbullet.ro/en/blog)

[GET in TOUCH](https://www.blackbullet.ro/contact-us)

Security Assessment

# \[🤓Geek Alert!🚨\] How SMEs around the world are affected by disclosed vulnerabilities?

SMEs worldwide are affected by disclosed vulnerabilities in the FTP, FTPS, SFTP, HTTP, HTTPS, and WebDAV protocols. The CrushFTP and 🚨CVE-2025-2825 🚨

[Ionut Staniu](https://www.blackbullet.ro/en/blog/author/ionut-staniu)

 Apr 4, 2025

---

🚨[CVE-2025-2825](https://nvd.nist.gov/vuln/detail/CVE-2025-0282) 🚨: Remote and unauthenticated HTTP requests to CrushFTP may allow attackers to gain unauthorized access.

CrushFTP is a widely used enterprise-grade file transfer server, which recently has disclosed that its versions 10.0.0 through 10.8.3  and 11.0.0 through 11.3.0 have a critical authentication bypass  flaw.

🔎 Performing some small #OSINT queries on #shodan, #hunter, #censys or even a Google dork *intitle:"CrushFTP WebInterface" inurl:/WebInterface/Login.html* you can identify thousands of possible vulnerable endpoints.

This type of attack can have an immediate impact via successful exploitation or can be chained to a more complex attack technique for a bigger impact on companies.

👇Query:

[🔎 SHODAN](https://www.shodan.io/search?query=server%3A+CrushFTP+HTTP+Server): server: CrushFTP HTTP Server

[🔎 Romania Filtered SHODAN:](https://www.shodan.io/search?query=server%3A+CrushFTP+HTTP+Server+country%3A%22RO%22&page=2) server: CrushFTP HTTP Server country:"RO"

🗂️Full reference:[https://securityonline.info/crushftp-hacked-exploit-cve-2025-2825-with-poc-and-nuclei-template/…](https://securityonline.info/crushftp-hacked-exploit-cve-2025-2825-with-poc-and-nuclei-template/%E2%80%A6) [https://rapid7.com/blog/post/2025/03/25/etr-notable-vulnerabilities-in-next-js-cve-2025-29927/…](https://rapid7.com/blog/post/2025/03/25/etr-notable-vulnerabilities-in-next-js-cve-2025-29927/%E2%80%A6)

🧐Deep Dive on the whole PoC: [https://projectdiscovery.io/blog/crushftp-authentication-bypass…](https://projectdiscovery.io/blog/crushftp-authentication-bypass%E2%80%A6)

PoC Summary using nuclei [template](https://cloud.projectdiscovery.io/public/CVE-2025-2825) for successful exploit validation.

### 💡Solution: “*Update to version 10.8.4+ or 11.3.1+ immediately*.”

[Security Assessment](https://www.blackbullet.ro/en/blog/tag/security-assessment) [Vulnerability Assessment](https://www.blackbullet.ro/en/blog/tag/vulnerability-assessment)

## Similar posts

<https://www.blackbullet.ro/en/blog/5-truths-about-nis-2-cybersecurity-that-leaders-cant-ignore>

Security Assessment

### [5 Truths About  NIS 2 Cybersecurity That Leaders Can't Ignore](https://www.blackbullet.ro/en/blog/5-truths-about-nis-2-cybersecurity-that-leaders-cant-ignore)

Discover five critical insights from the NIS 2 Directive that every business leader must understand to ensure cybersecurity resilience and compliance.

 Madalin Staniu  Feb 4, 2026

<https://www.blackbullet.ro/en/blog/cybersecurity-challenges-for-smes-in-romania-and-europe>

Security Assessment

### [Cybersecurity Challenges for SMEs in Romania and Europe](https://www.blackbullet.ro/en/blog/cybersecurity-challenges-for-smes-in-romania-and-europe)

SMEs are increasingly exposed to cyber risks, and attackers exploit any security weakness. What cyber threats affect SMEs the most?

 Ionut Staniu  Apr 10, 2025

<https://www.blackbullet.ro/en/blog/zero-trust-and-microsegmentation-incremental-approach>

Security Assessment

### [Zero Trust and Microsegmentation - Incremental Approach](https://www.blackbullet.ro/en/blog/zero-trust-and-microsegmentation-incremental-approach)

Learn how to implement Zero Trust and microsegmentation incrementally to reduce risks, manage complexity, and align with authoritative guidance for a...

 Madalin Staniu  Aug 14, 2025

![Black Bullet_white](https://www.blackbullet.ro/hubfs/Black%20Bullet_white.png)

21 Elena Caragiani Street, Bucharest, Romania  
+40743055072  
shoot@blackbullet.ro

### Our Services

- [NIS 2 Compliance](https://www.blackbullet.ro/en/nis-2-consultancy-and-implementation-services)
- [Penetration Testing](https://www.blackbullet.ro/cyber-security/penetration-testing)
- [Security Risk Assessent](https://www.blackbullet.ro/cyber-security/security-assessment)
- [GRC](https://www.blackbullet.ro/cyber-security/grc-governance-risk-compliance)
- [Security by Design Software Development](https://www.blackbullet.ro/software-development-services/)

### Company

- [About us](https://www.blackbullet.ro/about)
- [Contact us](https://www.blackbullet.ro/contact-us)
- [Discover your digital footprint](https://www.blackbullet.ro/cyber-security/get-digital-footprint-report/)

© 2026 Black Bullet - On target digital solutions All rights reserved [Privacy Policy](https://www.blackbullet.ro/privacy-policy)

[Powered by Atlas - a B2B SaaS HubSpot theme](https://www.kalungi.com/atlas-hubspot-theme-for-b2b-saas-software)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Ionut Staniu",
    "url" : "https://www.blackbullet.ro/en/blog/author/ionut-staniu"
  },
  "dateModified" : "2025-08-06T07:46:34.497Z",
  "datePublished" : "2025-04-04T05:57:16.000Z",
  "headline" : "[🤓Geek Alert!🚨] How SMEs around the world are affected by disclosed vulnerabilities?",
  "image" : [ "https://www.blackbullet.ro/hubfs/AI-Generated%20Media/Images/The%20image%20depicts%20a%20digital%20landscape%20filled%20with%20abstract%20representations%20of%20cybersecurity%20threats%20Central%20to%20the%20composition%20is%20a%20stylized%20large%20padlock%20symbolizing%20security%20which%20is%20cracked%20and%20partially%20open%20suggesting%20vulnerability%20Surrounding%20t-1.jpeg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.blackbullet.ro/en/blog/geek-alert-how-smes-around-the-world-are-affected-by-disclosed-vulnerabilities",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.blackbullet.ro/hubfs/BlackBullet_-2.png"
    },
    "name" : "INNOVATION NEEDS SRL"
  }
}
```