CVE-2025-54305

7.8

Thermo Fisher · Torrent Suite

The LocalhostAuthMiddleware in Thermo Fisher Torrent Suite 5.18.1 allows local users to bypass authentication by spoofing the REMOTE_ADDR header to localhost addresses.

Executive summary

A vulnerability in the Thermo Fisher Torrent Suite authentication middleware allows local attackers to gain unauthorized administrative access, posing a severe risk to system integrity.

Vulnerability

The application utilizes a flawed middleware component, LocalhostAuthMiddleware, which automatically elevates users to the ionadmin privilege level if the request originates from a localhost IP address. This flaw permits any user with local access to the server to bypass standard authentication mechanisms entirely.

Business impact

Successful exploitation grants an attacker full administrative control over the Torrent Suite application. Given the CVSS score of 7.8, this vulnerability represents a high-severity risk that could lead to complete system compromise, unauthorized data modification, or service disruption, necessitating immediate attention to secure the affected infrastructure.

Remediation

Immediate Action: Contact Thermo Fisher support immediately to obtain the appropriate security patch or configuration hardening instructions for the Torrent Suite 5.18.1 software.

Proactive Monitoring: Review system and application access logs for suspicious administrative logins originating from local loopback addresses or unexpected user accounts.

Compensating Controls: Restrict local system access to authorized personnel only and ensure that the server environment is hardened to prevent unauthorized users from executing commands or accessing the local network interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The reliance on network source headers for authentication is a significant security oversight that facilitates unauthorized administrative access. Organizations running Torrent Suite 5.18.1 should prioritize restricting physical and logical access to the host machine until a vendor-supplied patch is successfully deployed.

More Thermo Fisher CVEs

Sources