← Vulnerability feed

Vulnerability record · CVE-2024-23692 · published 31 May 2024

CVE-2024-23692: Rejetto HTTP File Server template injection leads to unauthenticated RCE

Rejetto · Http File Server

Rejetto HTTP File Server through version 2.3m is vulnerable to template injection, allowing a remote unauthenticated attacker to execute arbitrary commands via a crafted HTTP request. The flaw is critical because it requires no credentials or user interaction and the affected version is no longer supported, so no vendor patch is expected.

9.8 CVSS 3.1 Critical CISA KEV since 9 Jul 2024 Known ransomware use EPSS 99% · top 0.1% CWE-1336 · CWE-1336CWE-94 · Code injection
9.8CVSS 3.1 base score
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
10References, 7 tagged exploit
11 Aug 2026Last modified by NVD

Description

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, KEV listing with known ransomware use, near-maximum EPSS, and public exploit code make this an urgent patch-or-remove case.

What it is

Rejetto HTTP File Server through version 2.3m is vulnerable to template injection, allowing a remote unauthenticated attacker to execute arbitrary commands via a crafted HTTP request. The flaw is critical because it requires no credentials or user interaction and the affected version is no longer supported, so no vendor patch is expected.

Impact

An attacker gains arbitrary command execution on the host running HFS, typically leading to full system compromise under the service account. Given KEV listing with known ransomware use, this can serve as an initial access vector for broader intrusion.

Attack surface

Reachable over the network through the HFS HTTP interface; the CVSS vector shows no privileges required and no user interaction, so any exposed instance is directly attackable.

Exploitation

CVE-2024-23692 is in CISA KEV with known ransomware campaign use, EPSS probability is about 0.995 (99.9th percentile), and multiple references are tagged Exploit including a Metasploit module, indicating active and public exploitation.

What to do

  • Discontinue use of Rejetto HFS 2.3m or migrate to a supported file server, since the affected version is end-of-life and no vendor patch exists.
  • If HFS must remain, remove it from internet exposure and restrict access to trusted internal networks only.
  • Apply vendor or CISA-recommended mitigations and compensating controls such as network segmentation and least-privilege service accounts.
  • Hunt for and remove any existing HFS installations, then verify no unauthorized persistence or web shells were left behind.
  • Monitor CISA KEV guidance and apply the required action by the listed due date.

Detection

  • Inspect HTTP request logs for HFS template syntax or macro expressions in request parameters, headers, or paths.
  • Alert on HFS process spawning child processes such as cmd.exe, powershell.exe, or /bin/sh.
  • Search hosts for hfs.exe or Rejetto HFS artifacts and correlate with outbound connections or new listening services.
  • Review network traffic to HFS ports for anomalous POST or GET requests containing encoded command strings.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-23692 to the Known Exploited Vulnerabilities catalog on 9 July 2024 as "Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 30 July 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-23692 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-6287Rejetto HTTP File Server null byte code injection in findMacroMarkerThe findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS) 2.3x before 2.3c mishandles a %00 sequence in a search action, allowi…KEVEPSS 99%analysed8.8CVE-2024-39943Rejetto http file server os command injection vulnerabilityrejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have…EPSS 39%7.5CVE-2020-13432Rejetto http file server classic buffer overflow vulnerabilityrejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer wr…EPSS 31%7.5CVE-2014-7226Rejetto http file server code injection vulnerabilityThe file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file wit…EPSS 9.2%10.0CVE-2026-75650Adobe Commerce template engine flaw allows unauthenticated remote code executionAdobe Commerce, Commerce B2B and Magento are affected by improper neutralization of special elements used in a template engine (CWE-1336), allowing a…KEVEPSS 3.9%analysed10.0CVE-2024-4040CrushFTP server-side template injection enables unauthenticated sandbox escape and RCECrushFTP versions before 10.7.1 and 11.1.0 contain a server-side template injection flaw that lets unauthenticated remote attackers escape the VFS sa…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-23692), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.