CVE-2024-23692

CRITICAL KEV RANSOMWARE NUCLEI

Rejetto HTTP File Server - Template injection

Title source: nuclei

Description

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

Exploits (17)

exploitdb SCANNER
by VeryLazyTech · pythonwebappstypescript
https://www.exploit-db.com/exploits/52102
nomisec WORKING POC 43 stars
by verylazytech · remote
https://github.com/verylazytech/CVE-2024-23692
nomisec WORKING POC 16 stars
by jakabakos · remote
https://github.com/jakabakos/CVE-2024-23692-RCE-in-Rejetto-HFS
nomisec WORKING POC 13 stars
by 0x20c · remote
https://github.com/0x20c/CVE-2024-23692-EXP
nomisec WORKING POC 10 stars
by vanboomqi · remote
https://github.com/vanboomqi/CVE-2024-23692
nomisec WORKING POC 6 stars
by BBD-YZZ · remote
https://github.com/BBD-YZZ/CVE-2024-23692
nomisec WORKING POC 3 stars
by NanoWraith · poc
https://github.com/NanoWraith/CVE-2024-23692
nomisec WORKING POC 1 stars
by NingXin2002 · remote
https://github.com/NingXin2002/HFS2.3_poc
nomisec WORKING POC 1 stars
by pradeepboo · poc
https://github.com/pradeepboo/Rejetto-HFS-2.x-RCE-CVE-2024-23692
nomisec WORKING POC
by wgetnz · poc
https://github.com/wgetnz/hfs2
nomisec WORKING POC
by 999gawkboyy · remote
https://github.com/999gawkboyy/CVE-2024-23692_Exploit
nomisec WORKING POC
by Tupler · remote
https://github.com/Tupler/CVE-2024-23692-exp
nomisec WORKING POC
by Mr-r00t11 · remote
https://github.com/Mr-r00t11/CVE-2024-23692
nomisec WORKING POC
by WanLiChangChengWanLiChang · remote
https://github.com/WanLiChangChengWanLiChang/CVE-2024-23692-RCE
vulncheck_xdb WORKING POC
remote
https://github.com/k3lpi3b4nsh33/CVE-2024-23692
metasploit WORKING POC EXCELLENT
by sfewer-r7, Arseniy Sharoglazov · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/rejetto_hfs_rce_cve_2024_23692.rb

Nuclei Templates (1)

Rejetto HTTP File Server - Template injection
CRITICALVERIFIEDby johnk3r
Shodan: product:"HttpFileServer httpd"

Scores

CVSS v3 9.8
EPSS 0.9430
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2024-07-09
VulnCheck KEV 2024-06-28
InTheWild.io 2024-07-09
ENISA EUVD EUVD-2024-21153
Ransomware Use Confirmed
CWE
CWE-1336 CWE-94
Status published
Products (1)
rejetto/http_file_server < 2.4
Published May 31, 2024
KEV Added Jul 09, 2024
Tracked Since Feb 18, 2026