Authentication Bypass in Thermo Fisher Torrent Suite
CVE-2025-54305
7.8HIGH
What is CVE-2025-54305?
A security flaw has been identified in the Thermo Fisher Torrent Suite application version 5.18.1, specifically within the LocalhostAuthMiddleware. This vulnerability allows users with local access to the server to bypass authentication through manipulation of the REMOTE_ADDR property in the request.META. When this property is set to 127.0.0.1, 127.0.1.1, or ::1, the middleware erroneously authenticates the user as 'ionadmin', posing a significant risk to the integrity of the system. Organizations using this application should take immediate precautions to mitigate potential unauthorized access.
