CVE-2024-4040
KEVCRITICAL 10.0EPSS 99.5%
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 99.54% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-04-24
- Nuclei
- critical
- Published
- 2024-04-22
- Updated
- 2025-10-21
Proof-of-concept exploits (24)
- airbus-cert/CVE-2024-404055★ · 2024-05-17
- 0xN7y/CVE-2024-40400★ · 2024-04-28
- 1ncendium/CVE-2024-40400★ · 2024-05-13
- Mohammaddvd/CVE-2024-40405★ · 2024-04-30
- Mufti22/CVE-2024-40400★ · 2024-04-25
- Praison001/CVE-2024-4040-CrushFTP-server0★ · 2024-04-29
- Stuub/CVE-2024-4040-SSTI-LFI66★ · 2024-07-07
- Stuub/CVE-2024-4040-SSTI-LFI-PoC66★ · 2024-07-07
- entroychang/CVE-2024-40403★ · 2024-07-09
- geniuszly/GenCrushSSTIExploit8★ · 2024-09-30
- geniuszlyy/GenCrushSSTIExploit8★ · 2024-09-30
- gotr00t0day/CVE-2024-40407★ · 2024-05-04
- ill-deed/CrushFTP-CVE-2024-4040-illdeed0★ · 2025-07-04
- jakabakos/CVE-2024-4040-CrushFTP-File-Read-vulnerability4★ · 2024-05-02
- olebris/CVE-2024-40400★ · 2024-06-28
- rahisec/CVE-2024-40400★ · 2024-10-23
- rbih-boulanouar/CVE-2024-404014★ · 2024-04-25
- safeer-accuknox/CrushFTP-cve-2024-4040-poc0★ · 2024-10-16
- tongchengbin/nuclei-sdk2★ · 2026-07-26
- GraySignal/CVE-2024-4040-CrushFTP-server
- Sidjaz/CrushFTP-CVE-2024-4040-Proof-of-Concept
- dhammerg/CVE-2024-4040
- juanorts/CrushFTP10-Docker-CVE-2024-4040
- getdrive/PoC