Skip to content
COOEY

FAIL › dossier

Rejetto

VENDOR

· dossier confidence 25%

Rejetto's HTTP File Server has a history of critical, exploitable vulnerabilities, indicating significant security weaknesses. Their product's security posture requires immediate and substantial improvement to mitigate risk.

PROFILE
CategorySoftware VendorWhat they doRejetto develops the HTTP File Server (HFS), a web-based file management application. It provides a user-friendly interface for managing files on a web server. Websitehttps://www.rejetto.com/hfs/ ↗
SECURITY POSTURE

Rejetto has a history of critical remote code execution vulnerabilities in their HTTP File Server product. Their security practices appear to be lacking, as vulnerabilities have persisted and been exploited.

Notable failures
  • CVE-2024-23692 (RCE) - Template Engine Injection
  • CVE-2014-6287 (RCE) - parserLib.pas vulnerability
Patterns: Recurring remote code execution vulnerabilities; Lack of timely patching
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2024-07-09 CVE-2024-23692 high Rejetto HTTP File Server allows remote, unauthenticated attackers to execute arbitrary commands via template engine injection.
2022-03-25 CVE-2014-6287 high Rejetto HTTP File Server (HFS) suffered a remote code execution vulnerability that allowed attackers to execute arbitrary programs on affected systems.
2024-05-31 CVE-2024-23692 critical CVE-2024-23692: Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a t
Open questions: What is the current status of CVE-2014-6287? · What is the current ownership structure of Rejetto?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-04 04:10:17.841950+00:00