Active exploitation now makes HFS’s predictable session-signing keys an unauthenticated server-execution path.
Rejetto HFS, a self-hosted HTTP file server for Windows, Linux, macOS, FreeBSD and Android.
The attacker needs a network-reachable HFS 3.x server and a login-enabled username available through the documented enumeration oracle.
Detail and 3 sources
Consecutive Math.random outputs reveal recoverable xorshift128+ state, which yields the startup signing key used to forge an administrator session.
HFS 3.2.1 is published as the fixed release.
Today’s change is the complete root cause and execution chain, accompanied by observed exploitation.