CVE-2024-12645

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Dec 16, 2024
CWE ID 23
CWE ID 352

Summary

CVE-2024-12645 is a newly disclosed vulnerability affecting the topm-client software from Chunghwa Telecom. This application, which sets up a local web server for communication with target websites, is found to have two significant issues. Firstly, it lacks Cross-Site Request Forgery (CSRF) protection for its APIs, enabling unauthenticated remote attackers to manipulate these interfaces via phishing techniques. Secondly, one of the APIs contains a Relative Path Traversal flaw, allowing adversaries to read arbitrary files on the user's system. These vulnerabilities pose a severe risk, and affected users are urged to update their software as soon as a patch becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share