Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
https://www.infosecurity-magazine.com/news/russian-cyber-spies-hatvibe/
https://www.recordedfuture.com/research/russia-aligned-tag-110-targets-asia-and-europe
https://thehackernews.com/2024/07/ukrainian-institutions-targeted-using.html
https://vulncheck.com/advisories/rejetto-unauth-rce
https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/