CVE-2024-23692
KEV RANSOMWARECRITICAL 9.8EPSS 99.5%
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 99.47% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-07-09, used in ransomware campaigns
- Nuclei
- critical · CWE-1336
- Published
- 2024-05-31
- Updated
- 2026-08-11
Proof-of-concept exploits (17)
- https://www.vicarius.io/vsociety/posts/cve-2024-23692-detect-rejetto-hfs-vulnerability
- https://www.vicarius.io/vsociety/posts/cve-2024-23692-rejetto-hfs-mitigate-vulnerability
- https://www.vicarius.io/vsociety/posts/unauthenticated-rce-flaw-in-rejetto-http-file-serv…
- 0x20c/CVE-2024-23692-EXP13★ · 2024-06-18
- 999gawkboyy/CVE-2024-23692_Exploit0★ · 2025-03-06
- BBD-YZZ/CVE-2024-236927★ · 2024-06-18
- Mr-r00t11/CVE-2024-236920★ · 2024-06-14
- NanoWraith/CVE-2024-236924★ · 2024-06-11
- NingXin2002/HFS2.3_poc1★ · 2024-12-21
- Tupler/CVE-2024-23692-exp0★ · 2024-06-16
- WanLiChangChengWanLiChang/CVE-2024-23692-RCE0★ · 2024-06-13
- jakabakos/CVE-2024-23692-RCE-in-Rejetto-HFS16★ · 2024-06-13
- k3lpi3b4nsh33/CVE-2024-236924★ · 2024-06-11
- pradeepboo/Rejetto-HFS-2.x-RCE-CVE-2024-236921★ · 2024-07-10
- vanboomqi/CVE-2024-2369211★ · 2024-06-15
- verylazytech/CVE-2024-2369248★ · 2025-03-24
- sandimfz/CVE-2024-23692