Rejetto HFS (HTTP File Server) 3 versions before 0.52.10 on Linux, UNIX, and macOS contain an OS command-injection flaw. The application invokes the df utility through a shell using Node.js child_process.execSync rather than spawnSync. A remote authenticated user granted Upload permissions can exploit this behavior to execute operating-system commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository demonstrates a proof-of-concept (PoC) exploit for CVE-2024-39943, a remote code execution (RCE) vulnerability in a Node.js HFS-like server. The vulnerability arises because the server reads the content of an uploaded file and executes it directly as a shell command using child_process.execSync(). The repository includes: - A vulnerable Node.js server (app/server.js) that exposes an /upload endpoint for file uploads. Uploaded file contents are executed as shell commands, and the output is returned to the client. - A Dockerfile and docker-compose.yml for easy setup and deployment of the vulnerable server. - A Python PoC script (poc.py) that uploads a file containing a shell command to the /upload endpoint and prints the server's response, demonstrating successful RCE. - A README.md with detailed instructions and explanation of the vulnerability and exploitation steps. The main exploit capability is remote code execution via file upload to the /upload endpoint. The repository is structured for demonstration and educational purposes, highlighting the dangers of executing untrusted input as system commands.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CVE identifier incorrectly applied within the operator's toolkit to a technique it does not describe; the content provides no valid vulnerability details or confirmed relationship to the camera compromises.
A vulnerability reference found in the toolkit but explicitly not exploited in the observed CameraSwarm attacks.
A command-injection vulnerability in Rejetto HTTP File Server that is explicitly mentioned only to note it was incorrectly referenced by the attacker tooling and is not the Dahua camera backdoor technique discussed.
An operating-system command-injection vulnerability in Rejetto HFS mentioned only to clarify it is unrelated to the Dahua P2P behavior.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.