CVE-2025-54123General(hoverfly / hoverfly)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch hoverfly hoverfly systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injection vulnerability at `/api/v2/hoverfly/middleware` endpoint due to insufficient validation and sanitization in user input. The vulnerability exists in the middleware management API endpoint `/api/v2/hoverfly/middleware`. This issue is born due to combination of three code level flaws: Insufficient Input Validation in middleware.go line 94-96; Unsafe Command Execution in local_middleware.go line 14-19; and Immediate Execution During Testing in hoverfly_service.go line 173. This allows an attacker to gain remote code execution (RCE) on any system running the vulnerable Hoverfly service. Since the input is directly passed to system commands without proper checks, an attacker can upload a malicious payload or directly execute arbitrary commands (including reverse shells) on the host server with the privileges of the Hoverfly process. Commit 17e60a9bc78826deb4b782dca1c1abd3dbe60d40 in version 1.12.0 disables the set middleware API by default, and subsequent changes to documentation make users aware of the security changes of exposing the set middleware API.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hoverfly

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-07); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
hoverfly

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-07: 1Mentions · 2026-05-28: 1Mentions · 2026-07-04: 1PoC Mentioned / Linked · 2026-07-04: 1Exploit Tool / Code · 2026-07-04: 1Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-07-04: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-28: 1Technical Details · 2026-07-04: 105-0705-2807-04
Signal classification3 categories
General
133.3%
Disclosure
133.3%
Exploit
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-071
General1
2026-05-281
Disclosure1
2026-07-041
Exploit1
Full discourse3 posts
  • 1337@iamvivekz
    General

    🔓 Rooted DevArea on @HackTheBox! Anon FTP → JAR decompile → CVE-2022-46364 (CXF LFI) → CVE-2025-54123 (HoverFly RCE) → Binary hijack → ROOT 👑 Full writeup 👇 📝 Medium: https://medium.com/@DaakuDaddy/devarea-walthrough-hack-the-box-08d9a27663b1 💼 LinkedIn: https://www.linkedin.com/in/vivekgoswmii #HackTheBox #ctf https://labs.hackthebox.com/achievement/machine/2310429/859

    Post summary

    The post outlines a successful exploit chain in a HackTheBox machine using CVE‑2022‑46364 (CXF LFI) and CVE‑2025‑54123 (HoverFly RCE) to achieve root, but it provides no PoC, tool, or defense details.

    001402.8K
    79 followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    HTB DevArea (retired): a four-layer Linux attack chain walks through CVE-2022-46364 arbitrary file read, Hoverfly CVE-2025-54123 command injection, Flask cookie forgery, and a symlink-chain bypass in a sudo script. - CVE-2022-46364 (Apache CXF before 3.4.10/3.5.5) lets an attacker embed an xop:Include href="file:///..." element inside a multipart/related MTOM SOAP request. The server fetches the path, base64-encodes the bytes, and reflects them in the response. The employee-service.jar on the anonymous FTP server fingered the vulnerable CXF 3.2.14 version before a packet was sent. Reading /proc/self/cmdline and /proc/[pid]/cmdline exposed the Hoverfly process command line in plaintext, leaking creds: admin:O7IJ27MyyXiU. - CVE-2025-54123 (Hoverfly 1.11.3): a PUT to /api/v2/hoverfly/middleware with JSON body {"binary":"/bin/bash","script":"..."} passes user-controlled values directly to exec.Command without sanitization. The server runs the script as the service user, giving a shell as dev_ryan. The fix in 1.12.0 disables the middleware API by default. - The SysWatch Flask app stores its SECRET_KEY in /etc/syswatch.env with chmod 755 (world-readable). Reading that file via the CXF file-read lets an attacker forge a valid Flask session cookie (flask-unsign or Flask's own SecureCookieSessionInterface). #DFIR_Radar

    Post summary

    The post outlines a detailed Linux attack chain exploiting CVE-2022-46364 and CVE-2025-54123, provides practical exploitation steps, and notes a patch in Hoverfly 1.12.0.

    10010233
    1.7K followersView on X
  • BBWriteup@bbwriteup
    Disclosure

    "CVE-2025–54123 Hoverfly ≤1.11.3 Command Injection (RCE) Case Study & Patch Diffing" by phantom_hat #InfoSec #CyberSecurity #Hacking #Vulnerability https://medium.com/@phantom_hat/cve-2025-54123-hoverfly-1-11-3-command-injection-rce-case-study-patch-diffing-aacc092f7f3a

    Post summary

    The Medium article announces the Hoverfly command injection vulnerability (CVE‑2025‑54123), describes its impact, and provides patch diff information.

    0001050
    645 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphoverflyhoverfly---

Explore more