ATProto Browser

ATProto Browser

Experimental browser for the Atmosphere

Post

We are sharing unpatched CrushFTP instances likely vulnerable to CVE-2025-2825 (CVSS 9.8) that may allow unauthenticated remote attackers to bypass authentication via HTTP(S) requests. We see ~1800 unpatched instances worldwide, with over 900 in the US. dashboard.shadowserver.org/statistics/c...

Mar 28, 2025, 1:13 PM

Record data

{
  "uri": "at://did:plc:3xyh2kw5hfxsax4zff3pp5ub/app.bsky.feed.post/3llgveutlis2v",
  "cid": "bafyreifmhyvcplnc2ziizu6l5kom3y6prvtley4j2ox7s2ojywldqgnf5i",
  "value": {
    "text": "We are sharing unpatched CrushFTP instances likely vulnerable to CVE-2025-2825 (CVSS 9.8) that may allow unauthenticated remote attackers to bypass authentication via HTTP(S) requests. We see ~1800 unpatched instances worldwide, with over 900 in the US.\n\ndashboard.shadowserver.org/statistics/c...",
    "$type": "app.bsky.feed.post",
    "embed": {
      "$type": "app.bsky.embed.images",
      "images": [
        {
          "alt": "",
          "image": {
            "$type": "blob",
            "ref": {
              "$link": "bafkreia3z5d4eomgeii45xrlta73qzao7yp47zo3myrqbmpmjj35ohku5e"
            },
            "mimeType": "image/jpeg",
            "size": 791159
          },
          "aspectRatio": {
            "width": 2000,
            "height": 1004
          }
        }
      ]
    },
    "langs": [
      "en"
    ],
    "facets": [
      {
        "index": {
          "byteEnd": 297,
          "byteStart": 255
        },
        "features": [
          {
            "uri": "https://dashboard.shadowserver.org/statistics/combined/map/?map_type=std&day=2025-03-27&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-2825%2B&geo=all&data_set=count&scale=log",
            "$type": "app.bsky.richtext.facet#link"
          }
        ]
      }
    ],
    "createdAt": "2025-03-28T13:13:21.551Z"
  }
}