Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
https://www.infosecurity-magazine.com/news/russian-cyber-spies-hatvibe/
https://www.recordedfuture.com/research/russia-aligned-tag-110-targets-asia-and-europe
https://github.com/999gawkboyy/CVE-2024-23692_Exploit
https://github.com/nakataXmodem/cve-rce-poc
https://github.com/NingXin2002/HFS2.3_poc
https://github.com/XiaomingX/cve-2024-23692-poc
https://github.com/XiaomingX/CVE-2024-23692-poc
https://github.com/0x20c/CVE-2024-38856-EXP
https://github.com/pradeepboo/Rejetto-HFS-2.x-RCE-CVE-2024-23692
https://github.com/0x20c/CVE-2024-23692-EXP
https://github.com/BBD-YZZ/CVE-2024-23692
https://github.com/Tupler/CVE-2024-23692-exp
https://github.com/jakabakos/CVE-2024-23692-RCE-in-Rejetto-HFS
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23692
https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/