Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Rejetto — HTTP File Server
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
9.8
99.5%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- May 31, 2024
- Modified
- Aug 11, 2026
- Added to KEV
- Jul 9, 2024
- Federal patch due
- Jul 30, 2024
CISA required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2024-23692, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- verylazytech/CVE-2024-23692★ 48
POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692
updated Jun 6, 2026
- jakabakos/CVE-2024-23692-RCE-in-Rejetto-HFS★ 16
Unauthenticated RCE Flaw in Rejetto HTTP File Server (CVE-2024-23692)
updated Oct 16, 2025
- 0x20c/CVE-2024-23692-EXP★ 13
CVE-2024-23692 Exploit
updated Oct 4, 2025
- vanboomqi/CVE-2024-23692★ 11
updated Jul 14, 2026
- BBD-YZZ/CVE-2024-23692★ 7
CVE-2024-23692
updated Jul 8, 2026
- NanoWraith/CVE-2024-23692★ 4
updated Apr 14, 2026
- pradeepboo/Rejetto-HFS-2.x-RCE-CVE-2024-23692★ 1
Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)
updated Aug 4, 2024
- NingXin2002/HFS2.3_poc★ 1
HFS2.3未经身份验证的远程代码执行(CVE-2024-23692)
updated Dec 26, 2024
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2024-23692?
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
How severe is CVE-2024-23692?
CVE-2024-23692 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2024-23692 actively exploited in the wild?
Yes. CVE-2024-23692 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Jul 9, 2024, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2024-23692?
99.5% - meaning FIRST.org's EPSS model estimates a 99.5% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2024-23692?
Yes - a public Nuclei template referencing CVE-2024-23692 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2024-23692?
CVE-2024-23692 is classified under CWE-1336, CWE-94 (CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine).
Cross-checked against
Impactr finds and proves whether CVE-2024-23692 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist