<!-SC_OFF --><div class="md"><p>Head over to Netomize&#39;s blog to learn about how we detect the exploitation of the CrushFTP Vulnerability (CVE-2025-31161) with PacketSmith&#39;s Ya…
| CVE ID | CVE-2025-31161 |
| Vendor | reddit_netsec |
| Affected Product | Threat Intelligence |
| Vulnerability Type | Vulnerability |
| CVSS Score | 8.0 (HIGH) |
| Actively Exploited | ✅ Yes |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via reddit_netsec) |
<!-- SC_OFF --><div class="md"><p>Head over to Netomize&#39;s blog to learn about how we detect the exploitation of the CrushFTP Vulnerability (CVE-2025-31161) with PacketSmith&#39;s Yara detection module, using the newly introduced track_state and flow_state keywords to the correlation engine.</p> </div><!-- SC_ON --> &#32; submitted by &#32; <a href="https://www.reddit.com/user/MFMokbel"> /u/MFMokbel </a> <br/> <span><a href="https://blog.netomize.ca/detecting-exploitation-of-crushftp-vulnerability-cve-2025-31161-with-packetsmith-yara-detection-module-using-track-state-and-flow-state">[link]</a></span> &#32; <span><a href="https://www.reddit.com/r/
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.