CyberRota Analysis
AI-GeneratedHFS2 versions 2.4.0 and earlier are vulnerable to a critical template injection flaw in the multipart upload handler, enabling unauthenticated attackers to execute arbitrary commands on the host system through crafted filenames. This vulnerability allows for remote code execution by bypassing authorization checks, posing a severe risk to systems running affected versions. Organizations using HFS2 should prioritize immediate patching or mitigation efforts to safeguard against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.