CVE-2025-54307
8.8Thermo Fisher · Torrent Suite
Thermo Fisher Torrent Suite 5.18.1 contains a path traversal vulnerability in multiple upload endpoints, allowing authenticated low-privilege users to achieve remote code execution.
Executive summary
A path traversal vulnerability in Thermo Fisher Torrent Suite allows authenticated users to achieve remote code execution by overwriting critical system files.
Vulnerability
The application fails to sanitize file paths during ZIP file uploads within the plupload_file_upload function, enabling path traversal. An authenticated user can leverage this flaw to write arbitrary files to the server and trigger remote code execution by overwriting executable components.
Business impact
The ability for an authenticated user to perform remote code execution poses a critical threat to the integrity and availability of laboratory data systems. A successful exploit could lead to full system compromise, unauthorized data access, and significant operational downtime for research environments. With a CVSS score of 8.8, this vulnerability represents a high-risk entry point that necessitates immediate attention.
Remediation
Immediate Action: Contact Thermo Fisher support to obtain the latest security patches or configuration guidance for Torrent Suite 5.18.1, as no public fix is currently documented.
Proactive Monitoring: Audit server logs for suspicious POST requests to the /configure/plugins/plugin/upload/zip/ or /configure/newupdates/offline/bundle/upload/ endpoints.
Compensating Controls: Implement strict network access control lists to restrict access to the Torrent Suite management interface to authorized administrative personnel only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote code execution, this vulnerability must be treated as a priority for all organizations utilizing the Torrent Suite. Administrators should immediately restrict access to the affected endpoints and coordinate with the vendor to ensure that the system is updated to a patched version as soon as it becomes available.