Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

Published 7 Aug 2026Updated 7 Aug 202617 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

Affected versions

HTTP File Server: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 52102Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)VeryLazyTech2025-03-28VerifiedPoC-in-GitHub · NanoWraith/CVE-2024-23692★ 4NanoWraith2024-06-11CandidatePoC-in-GitHub · jakabakos/CVE-2024-23692-RCE-in-Rejetto-HFSUnauthenticated RCE Flaw in Rejetto HTTP File Server (CVE-2024-23692)★ 16jakabakos2024-06-13CandidatePoC-in-GitHub · vanboomqi/CVE-2024-23692★ 12vanboomqi2024-06-13CandidatePoC-in-GitHub · WanLiChangChengWanLiChang/CVE-2024-23692-RCE★ 0WanLiChangChengWanLiChang2024-06-13CandidatePoC-in-GitHub · Mr-r00t11/CVE-2024-23692Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.★ 0Mr-r00t112024-06-14CandidatePoC-in-GitHub · Tupler/CVE-2024-23692-expCVE-2024-23692 exp★ 0Tupler2024-06-16CandidatePoC-in-GitHub · BBD-YZZ/CVE-2024-23692CVE-2024-23692★ 7BBD-YZZ2024-06-17CandidatePoC-in-GitHub · 0x20c/CVE-2024-23692-EXPCVE-2024-23692 Exploit★ 130x20c2024-06-18CandidatePoC-in-GitHub · pradeepboo/Rejetto-HFS-2.x-RCE-CVE-2024-23692Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)★ 1pradeepboo2024-07-10CandidatePoC-in-GitHub · verylazytech/CVE-2024-23692POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692★ 48verylazytech2024-09-15CandidatePoC-in-GitHub · NingXin2002/HFS2.3_pocHFS2.3未经身份验证的远程代码执行(CVE-2024-23692)★ 1NingXin20022024-12-21CandidatePoC-in-GitHub · 999gawkboyy/CVE-2024-23692_ExploitHFS 2.3m SERVER RCE Vulnerability exploit★ 0999gawkboyy2025-03-06CandidatePoC-in-GitHub · wgetnz/hfs2CVE-2024-23692 | HFS 2.3m/2.4-RC07 RCE vulnerability fix★ 0wgetnz2026-02-26CandidatePoC-in-GitHub · sandimfz/CVE-2024-23692★ 0sandimfz2026-08-08Candidate