CVE-2024-12645
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-12645 is a newly disclosed vulnerability affecting the topm-client software from Chunghwa Telecom. This application, which sets up a local web server for communication with target websites, is found to have two significant issues. Firstly, it lacks Cross-Site Request Forgery (CSRF) protection for its APIs, enabling unauthenticated remote attackers to manipulate these interfaces via phishing techniques. Secondly, one of the APIs contains a Relative Path Traversal flaw, allowing adversaries to read arbitrary files on the user's system. These vulnerabilities pose a severe risk, and affected users are urged to update their software as soon as a patch becomes available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.