Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-39943 | rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload per rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js). NVD description · AI analysis pending | 8.8 | 37% |
| — | ||
| CVE-2024-23692 | Unauthenticated Template Injection RCE in Rejetto HTTP File Server 2.3m Rejetto HTTP File Server (HFS), a free Windows-based file-sharing server, contains a template injection vulnerability (CWE-94/CWE-1336) in versions up to and including 2.3m that allows a remote, unauthenticated attacker to execute arbitrary commands by sending a specially crafted HTTP request. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1: 9.8 Critical), and the affected 2.3m release is no longer supported by the vendor. Any system running Rejetto HFS 2.3m or earlier is affected, with instances exposed directly to the internet at the greatest risk. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-07-09 with known ransomware use, EPSS assigns a 99.5% probability of exploitation within 30 days, and public PoCs and a Metasploit module are available. Related reporting on Russia-aligned TAG-110 activity (HATVIBE/CHERRYSPY malware) against Ukrainian institutions highlights active targeting around the same period. Do: Because HFS 2.3m is end-of-life with no fixed 2.x version indicated in the available data, follow CISA's required action: apply mitigations per vendor instructions or discontinue use of the product, and at minimum remove it from direct internet exposure (firewall/ACL rules or VPN-only access). Hunt for compromise by checking HFS access logs for crafted HTTP requests containing template/macro syntax and the HFS service process for unexpected child processes. Organizations subject to CISA KEV remediation deadlines should prioritize this fix given the 9.8 Critical severity, 99.5% EPSS, and known ransomware use. | 9.8 | 99% | KEV ransomware PoC ×5 |
| largetens of thousands of internet-exposed HFS 2.3m instances (order of magnitude 10k–100k systems) | |
| CVE-2020-13432 | rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers. NVD description · AI analysis pending | 7.5 | 31% | PoC ×4 |
| — | |
| CVE-2014-6287 | Unauthenticated RCE in Rejetto HTTP File Server (HFS) via Template Macro Parsing CVE-2014-6287 is an unauthenticated remote code execution flaw in Rejetto HTTP File Server (HFS), a freeware file-sharing web server for Windows: the findMacroMarker function in parserLib.pas mishandles parsing of template macros, allowing code injection (CWE-94). An attacker triggers it by sending a crafted HTTP request whose specially crafted macro/special characters break out of the template parser, causing HFS to execute arbitrary commands or programs on the host. Successful exploitation yields command execution with the privileges of the HFS process, which is typically enough to install malware, ransomware, DDoS botnet components, or cryptocurrency miners on Windows systems. Any Windows host running Rejetto HFS is affected, particularly instances exposed directly to the internet; the source data does not list specific vulnerable version ranges. Exploitation is confirmed: the flaw was added to CISA's KEV on 2022-03-25 and carries a 99.3% EPSS (100th percentile), and related news links HFS exploitation to multi-exploit Windows malware campaigns such as the Lucifer DDoS botnet and the BlackSquid crypto-mining malware. Do: Upgrade HFS to the current vendor release (public advisories identify 2.3c, build 298, as the fixed build) per vendor instructions, as required by the CISA KEV action. If updating is not immediately possible, remove or restrict direct internet exposure (firewall the HFS port or place the service behind VPN/authentication) and review affected hosts for signs of compromise, such as unexpected cmd.exe/PowerShell child processes, new miner or botnet binaries, and unusual outbound traffic. | — | 99% | KEV |
| largetens of thousands of internet-exposed HFS instances (order of ~40,000-70,000, estimate) |