Exploit discussion active in current signal (1 latest mentions)
Immediate actions
Patch hoverfly hoverfly systems immediately
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: High priority (within 72h)
NVD description
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injection vulnerability at `/api/v2/hoverfly/middleware` endpoint due to insufficient validation and sanitization in user input. The vulnerability exists in the middleware management API endpoint `/api/v2/hoverfly/middleware`. This issue is born due to combination of three code level flaws: Insufficient Input Validation in middleware.go line 94-96; Unsafe Command Execution in local_middleware.go line 14-19; and Immediate Execution During Testing in hoverfly_service.go line 173. This allows an attacker to gain remote code execution (RCE) on any system running the vulnerable Hoverfly service. Since the input is directly passed to system commands without proper checks, an attacker can upload a malicious payload or directly execute arbitrary commands (including reverse shells) on the host server with the privileges of the Hoverfly process. Commit 17e60a9bc78826deb4b782dca1c1abd3dbe60d40 in version 1.12.0 disables the set middleware API by default, and subsequent changes to documentation make users aware of the security changes of exposing the set middleware API.
The post outlines a successful exploit chain in a HackTheBox machine using CVE‑2022‑46364 (CXF LFI) and CVE‑2025‑54123 (HoverFly RCE) to achieve root, but it provides no PoC, tool, or defense details.
HTB DevArea (retired): a four-layer Linux attack chain walks through CVE-2022-46364 arbitrary file read, Hoverfly CVE-2025-54123 command injection, Flask cookie forgery, and a symlink-chain bypass in a sudo script.
- CVE-2022-46364 (Apache CXF before 3.4.10/3.5.5) lets an attacker embed an xop:Include href="file:///..." element inside a multipart/related MTOM SOAP request. The server fetches the path, base64-encodes the bytes, and reflects them in the response. The employee-service.jar on the anonymous FTP server fingered the vulnerable CXF 3.2.14 version before a packet was sent. Reading /proc/self/cmdline and /proc/[pid]/cmdline exposed the Hoverfly process command line in plaintext, leaking creds: admin:O7IJ27MyyXiU.
- CVE-2025-54123 (Hoverfly 1.11.3): a PUT to /api/v2/hoverfly/middleware with JSON body {"binary":"/bin/bash","script":"..."} passes user-controlled values directly to exec.Command without sanitization. The server runs the script as the service user, giving a shell as dev_ryan. The fix in 1.12.0 disables the middleware API by default.
- The SysWatch Flask app stores its SECRET_KEY in /etc/syswatch.env with chmod 755 (world-readable). Reading that file via the CXF file-read lets an attacker forge a valid Flask session cookie (flask-unsign or Flask's own SecureCookieSessionInterface).
#DFIR_Radar
Post summary
The post outlines a detailed Linux attack chain exploiting CVE-2022-46364 and CVE-2025-54123, provides practical exploitation steps, and notes a patch in Hoverfly 1.12.0.
"CVE-2025–54123 Hoverfly ≤1.11.3 Command Injection (RCE) Case Study & Patch Diffing" by phantom_hat
#InfoSec#CyberSecurity#Hacking#Vulnerability
https://medium.com/@phantom_hat/cve-2025-54123-hoverfly-1-11-3-command-injection-rce-case-study-patch-diffing-aacc092f7f3a
Post summary
The Medium article announces the Hoverfly command injection vulnerability (CVE‑2025‑54123), describes its impact, and provides patch diff information.