CVE-2024-12643
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-12643 is a newly disclosed vulnerability affecting the tbm-client software from Chunghwa Telecom. The issue involves a combination of Cross-Site Request Forgery (CSRF) and Absolute Path Traversal vulnerabilities in the application's APIs. An attacker could exploit the lack of CSRF protection by luring users into clicking malicious links, gaining unauthorized access to delete arbitrary files on the user's system through the Absolute Path Traversal vulnerability. This poses a significant risk to users who rely on this software, making it essential for timely patches and updated security measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.