CVE-2025-54305
7.8Thermo Fisher · Torrent Suite
The LocalhostAuthMiddleware in Thermo Fisher Torrent Suite 5.18.1 allows local users to bypass authentication by spoofing the REMOTE_ADDR header to localhost addresses.
Executive summary
A vulnerability in the Thermo Fisher Torrent Suite authentication middleware allows local attackers to gain unauthorized administrative access, posing a severe risk to system integrity.
Vulnerability
The application utilizes a flawed middleware component, LocalhostAuthMiddleware, which automatically elevates users to the ionadmin privilege level if the request originates from a localhost IP address. This flaw permits any user with local access to the server to bypass standard authentication mechanisms entirely.
Business impact
Successful exploitation grants an attacker full administrative control over the Torrent Suite application. Given the CVSS score of 7.8, this vulnerability represents a high-severity risk that could lead to complete system compromise, unauthorized data modification, or service disruption, necessitating immediate attention to secure the affected infrastructure.
Remediation
Immediate Action: Contact Thermo Fisher support immediately to obtain the appropriate security patch or configuration hardening instructions for the Torrent Suite 5.18.1 software.
Proactive Monitoring: Review system and application access logs for suspicious administrative logins originating from local loopback addresses or unexpected user accounts.
Compensating Controls: Restrict local system access to authorized personnel only and ensure that the server environment is hardened to prevent unauthorized users from executing commands or accessing the local network interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The reliance on network source headers for authentication is a significant security oversight that facilitates unauthorized administrative access. Organizations running Torrent Suite 5.18.1 should prioritize restricting physical and logical access to the host machine until a vendor-supplied patch is successfully deployed.