CVE-2025-54305

HIGH

Thermo Fisher Torrent Suite 5.18.1 - Authentication Bypass via LocalhostAuthMiddleware Spoofing

Title source: llm
STIX 2.1

Description

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as ionadmin if the REMOTE_ADDR property in request.META is set to 127.0.0.1, to 127.0.1.1, or to ::1. Any user with local access to the server may bypass authentication.

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 3.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-290
Status published
Products (1)
thermofisher/torrent_suite_software 5.18.1
Published Dec 04, 2025
Tracked Since Feb 18, 2026