A walkthrough of exploiting a HackTheBox machine running CrushFTP and an Erlang SSH server. Two authentication bypass CVEs (CVE-2025-31161 and CVE-2025-54309) are demonstrated to gain admin access to CrushFTP. A PHP webshell is uploaded through the admin interface to achieve initial foothold. Hardcoded credentials are

20m read timeFrom 0xdf.gitlab.io
Post cover image
Table of contents
Box InfoReconShell as www-dataShell as benShell as root

Sort: