PT-2025-49042 · Thermo Fisher+1 · Torrent Suite+1

CVE-2025-54305

·

Published

2025-12-04

·

Updated

2025-12-16

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Thermo Fisher Torrent Suite Django Application version 5.18.1
Description The application’s LocalhostAuthMiddleware authenticates users as ionadmin if the request.META['REMOTE ADDR'] property is set to 127.0.0.1, 127.0.1.1, or ::1. This allows a user with local server access to bypass authentication. The affected component is a middleware within the application.
Recommendations Versions prior to 5.18.1 are affected.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54305

Affected Products

Django
Torrent Suite