CyberRota Analysis
AI-GeneratedRejetto HFS versions 3.0.0 to 3.2.0 are vulnerable due to their login endpoint revealing whether a submitted username is valid, which can be exploited by remote unauthenticated attackers to enumerate valid account names. This vulnerability increases the risk of password-guessing and session-forgery attacks, particularly targeting the default admin account. Organizations using affected versions should prioritize remediation to protect against potential unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can use this to confirm valid account names, including the default admin account, facilitating password-guessing and session-forgery attacks.