CVE-2024-12643

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Dec 16, 2024
CWE ID 352
CWE ID 36

Summary

CVE-2024-12643 is a newly disclosed vulnerability affecting the tbm-client software from Chunghwa Telecom. The issue involves a combination of Cross-Site Request Forgery (CSRF) and Absolute Path Traversal vulnerabilities in the application's APIs. An attacker could exploit the lack of CSRF protection by luring users into clicking malicious links, gaining unauthorized access to delete arbitrary files on the user's system through the Absolute Path Traversal vulnerability. This poses a significant risk to users who rely on this software, making it essential for timely patches and updated security measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share