FAIL › dossier
Rejetto
VENDOR· dossier confidence 25%
Rejetto's HTTP File Server has a history of critical, exploitable vulnerabilities, indicating significant security weaknesses. Their product's security posture requires immediate and substantial improvement to mitigate risk.
PROFILE
CategorySoftware VendorWhat they doRejetto develops the HTTP File Server (HFS), a web-based file management application. It provides a user-friendly interface for managing files on a web server.
Websitehttps://www.rejetto.com/hfs/ ↗
SECURITY POSTURE
Rejetto has a history of critical remote code execution vulnerabilities in their HTTP File Server product. Their security practices appear to be lacking, as vulnerabilities have persisted and been exploited.
Notable failures
- CVE-2024-23692 (RCE) - Template Engine Injection
- CVE-2014-6287 (RCE) - parserLib.pas vulnerability
Patterns: Recurring remote code execution vulnerabilities; Lack of timely patching
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-07-09 | CVE-2024-23692 | high | Rejetto HTTP File Server allows remote, unauthenticated attackers to execute arbitrary commands via template engine injection. |
| 2022-03-25 | CVE-2014-6287 | high | Rejetto HTTP File Server (HFS) suffered a remote code execution vulnerability that allowed attackers to execute arbitrary programs on affected systems. |
| 2024-05-31 | CVE-2024-23692 | critical | CVE-2024-23692: Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a t |
DOSSIER SOURCES
- Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find · www.cvefind.com
- Ebola Outbreak: Current Situation | Ebola | CDC · www.cdc.gov
- Chrome Releases · chromereleases.googleblog.com
Open questions: What is the current status of CVE-2014-6287? · What is the current ownership structure of Rejetto?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-04 04:10:17.841950+00:00