Home

Description

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as ionadmin if the REMOTE_ADDR property in request.META is set to 127.0.0.1, to 127.0.1.1, or to ::1. Any user with local access to the server may bypass authentication.

PUBLISHED Reserved 2025-07-18 | Published 2025-12-04 | Updated 2025-12-05 | Assigner mitre

References

www.thermofisher.com/...flow/ion-torrent-suite-software.html

assets.thermofisher.com/...0026163-Torrent-Suite-5.18-UG.pdf

documents.thermofisher.com/...and_Torrent_Suite_Software.pdf

cve.org (CVE-2025-54305)

nvd.nist.gov (CVE-2025-54305)